The Spanish Ministry of Science (Ministerio de Ciencia, Innovación y Universidades) has announced the partial shutdown of its IT systems, causing significant disruptions to services serving citizens, researchers and businesses. The decision comes at a time when cyber threats against public bodies are increasing, with state networks now a key target for attacks.

The ministry is responsible for policy-making in critical areas such as science, research, innovation and higher education. It also manages administrative platforms used by universities, students and research institutions, hosting highly sensitive data.
Suspension of procedures and extension of deadlines
According to an official announcement posted on the main page of the ministry's website, the online headquarters has been partially suspended "due to a technical incident that is under assessment." Although no further details were given, the effects are already apparent.
See also: Conpet cyberattack: Romania's national oil pipeline operator targeted
All current administrative procedures have been "frozen", with the ministry assuring that measures are being taken to protect the rights and legitimate interests of those affected. In order to limit the impact, an extension of all relevant deadlines has been announced, based on Article 32 of Law 39/2015, which provides for special management in cases of emergency service interruption.

Ministry of Science: Allegations of cyberattack
Although the initial announcement only referred to a "technical incident", a threat actor appeared on underground forums claiming to have carried out a cyberattack on the ministry's systems .
The perpetrator, who uses the alias "GordonFreeman" (a reference to the well-known character in the game Half-Life), allegedly offered data attributed to the Spanish ministry for sale, soliciting bids from bidders.
According to the information, sample files were published as "proof" of the breach, which include personal data, email addresses, registration requests, as well as screenshots of official documents.
Exploiting critical IDOR vulnerability
The threat actor claims that access was gained through a critical Insecure Direct Object Reference (IDOR) vulnerability. This is a known security flaw that allows unauthorized users to gain access to data or functionality simply by modifying parameters in application requests.
See also: Conduent: New details about last year's data breach
The attacker claims that this vulnerability gave him “full administrator-level access,” which – if confirmed – would be a serious blow to the organization’s cybersecurity.

Ministry of Science: The situation remains unclear
Notably, the forum where the information appeared is now offline, and the data has not yet been posted on other platforms, making it difficult to independently verify the claims.
The leaked images appear authentic, but there is no official confirmation of their authenticity yet. Journalist sources report that the ministry was asked for comment, but there was no immediate response.
Confirmation from Spanish media
Meanwhile, Spanish media reports that a spokesperson for the Ministry of Science confirmed that the disruption was indeed related to a cyberattack. If true, the incident adds to the long list of cyberattacks affecting government organizations across Europe, highlighting the need to strengthen protection measures and address critical vulnerabilities more quickly.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Betterment: Data breach affects 1.4 million accounts
The next period is expected to be crucial, as authorities will need to clarify the extent of the breach and ensure that the data of citizens and institutions has not been further exposed.
Source: www.bleepingcomputer.com
