• 4 mins read
  • Published

Inmates Breach Data at Figueres Prison in Major Cyberattack

Richard Reid RUSSPAIN.com

Post by Richard Reid

Inmates Breach Data at Figueres Prison in Major Cyberattack RUSSPAIN.com © russpain.com
Inmates Breach Data at Figueres Prison in Major Cyberattack © russpain.com

Three inmates at Puig de les Basses prison accessed personal data of staff after a cyberattack. Unions warn the breach is more serious than first reported. Authorities are still investigating the full impact.

A serious security incident at the Puig de les Basses prison in Figueres has exposed personal information of prison staff after three inmates managed to breach the facility’s computer network in mid-August. According to union sources, the prisoners accessed names, ID numbers, email addresses, and even car registration details belonging to employees. The breach, which was initially downplayed by the Department of Justice and Quality Democracy, is now being described by unions as far more extensive than first acknowledged.

Investigators have determined that the inmates gained entry to 12 folders containing around 26,000 documents, some of which were shared between departments and could be accessed from multiple computers. Two of these folders were copied onto a device used by the prisoners. The accessed files included lists of staff who use electronic signature cards, corporate phone numbers of senior prison officials and volunteers, and vehicle registrations linked to staff identification numbers. The unions are demanding urgent measures to protect affected employees and greater transparency from the authorities.

Technical staff from the Department of Justice, led by the Director General of Prison Affairs, Domingo Estepa, have met with representatives from UGT, CC OO, and Catac to discuss the ongoing investigation and its consequences. The probe is being conducted under strict confidentiality by the cybercrime unit of the Mossos d’Esquadra’s Criminal Investigation Division and the Catalan Cybersecurity Agency, which is preparing a detailed audit of the incident. So far, officials say there is no evidence that the stolen data has been leaked or transferred to external devices, but they admit they cannot guarantee this with certainty while the investigation continues.

Authorities have assured unions that the attackers did not access the main staff portal, personnel files with photos, or banking information. However, the copied documents remain stored on a prison computer accessible to inmates. The Department of Justice has also stated that the full scope of affected individuals is still being determined, and all impacted staff will be notified in accordance with data protection regulations once the audit is complete. In response to union concerns, the administration is considering reinstating protected license plates for prison staff vehicles, a measure that had been discontinued in previous years.

Union representatives are also calling for accountability from the IT service provider, citing apparent negligence in system management. The three inmates identified as responsible for the breach have been transferred to separate facilities. None were serving sentences for cybercrimes, and the attack reportedly exploited vulnerabilities in the prison’s recently installed touchscreen video call terminals. The breach was detected after system alarms were triggered and another inmate alerted staff to suspicious activity.

Cybersecurity incidents in Spanish institutions have become more frequent in recent years, highlighting the need for robust digital safeguards in sensitive environments. The Figueres case follows other high-profile breaches, such as the arrest of a serial impostor in Madrid who targeted judicial systems, as reported in a related investigation. Experts note that the growing sophistication of attacks requires continuous updates to security protocols and closer cooperation between authorities and staff representatives. The final report from the Catalan Cybersecurity Agency is expected to clarify the full extent of the Figueres breach and guide future preventive measures.

Also read