The Port of Vigo suffered a cyberattack early Tuesday morning, disrupting cargo management systems and forcing authorities to shut down access to key digital services. The cyberattack was detected around 5:45 a.m., prompting an immediate response from the port's IT team.

The incident, now confirmed as a ransomware attack, affected the servers connected to the Port Authority website, which was taken offline. While the technical team managed to contain the threat, the systems have been isolated from external networks as a precautionary measure.
The port's president, Carlos Botana, said the systems will not be back in operation until all safety checks are completed. He noted that the team is waiting until "everything is clear" before reconnecting services. At this stage, there is no confirmed timeline for when normal operations will resume.
See also: Device code phishing attack has targeted 340+ organizations
Port of Vigo: Disruption of daily activities
The cyberattack on the Port of Vigo has not affected the physical operation of the port, but has significantly disrupted daily operations. Much of the cargo management process depends on digital platforms for planning, coordination and documentation.
With the systems down, port users have been forced to turn to manual methods. Some operations, including those at the Border Inspection Point (BIP), are now managed using paper documents to maintain workflows.
This alternative has helped avoid a complete shutdown, but it slows down processes and adds pressure on staff. The situation reflects how dependent modern port operations have become on digital infrastructure.

Ransomware behind the attack on the port
Authorities have confirmed that the cyberattack on the Port of Vigo involved ransomware, a type of malware that blocks access to systems or data until the victim pays a ransom. In many cases, the attackers also extract sensitive data, increasing the risk of further exposure.
See also: Red Menshen: Using BPFDoor for espionage through telecommunications networks
In this case, the focus remains on containment and recovery. An investigation is underway to determine how the attackers gained access and whether data has been breached.
Despite progress in containing the attack, the Port Authority has made it clear that restoring systems will take time. The IT team has not provided an estimated timeline for the servers to resume activity, citing the need for full security validation before systems can be reconnected.
“Operational services and the physical operation of the port have not been affected, but the programs will not reopen to the public until all safety checks,” Botana said.
This cautious approach is becoming increasingly common in ransomware cases, where early remediation can lead to reinfection or further breach.
Ransomware attacks target critical infrastructure
The cyberattack on the Port of Vigo highlights the growing risk that ransomware poses to critical infrastructure. Ports, in particular, rely on a mix of physical operations and digital systems, making them vulnerable to disruptions that can impact both the supply chain and the flow of trade.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Although operations in Vigo have not stopped completely, the shift to manual procedures shows how quickly efficiency can be reduced when systems are offline.
See also: Nova Scotia Power: Data breach affects over 900,000 customers

The cyberattack incident also points to a broader trend: cyberattacks are no longer limited to data theft. They are increasingly designed to disrupt operations, creating an immediate and visible impact.
As the investigation into the cyberattack on the Port of Vigo continues, attention remains on the safe restoration of systems and understanding the scope of the breach. For now, the Port continues to operate under limited conditions, managing cargo traffic without the digital tools it usually relies on.
Source: thecyberexpress.com
