The prisoners of Figueres responsible for a cyberattack accessed personal information of officials

The prisoners of Figueres responsible for a cyberattack accessed personal information of officials

The three inmates who carried out a cyberattack at the Puig de les Basses Penitentiary Center in Figueres (Girona) in mid-August accessed documents such as the name, ID number, and email address of prison staff, as well as license plates of the personal cars of several officers. Although the Department of Justice and Democratic Quality refers to the initial statement issued on August 12, UGT sources warn that “the cyberattack is much more serious than initially stated.” The inmates, they claim, accessed 12 folders, 26,000 documents from both the Department of Justice and other departments, and two of these shared folders, which can be accessed from other computers, were copied onto one of the computers used. The unions demand “that the necessary measures be applied to minimize any risk to those affected” and “transparency.”

Read more Six Spanish hospitals participated in the melanoma vaccine trial

UGT, CC OO, and Catac union representatives have met with technical officials from the conselleria, led by the Director General of Penitentiary Affairs, Domingo Estepa, to learn about the progress of the investigation and the consequences of the cyberattack detected last Sunday, August 9, on the center’s shared network. The investigation, under secrecy of proceedings, is being conducted by the cybercrime unit of the Criminal Investigation Division (DIC) of the Mossos d’Esquadra and the Catalonia Cybersecurity Agency, which is preparing a report-audit on the consequences of this cyberattack.

According to UGT, Justice assures that “it can practically be ruled out that they accessed the officers’ portal or files with employee records or photographs, nor bank accounts.” And that “there is still no evidence that these documents copied in Backup have been leaked in any way anywhere, or copied to a USB device, as it is under investigation,” however, UGT maintains, “they also cannot guarantee that this has not happened.” The documents were indeed saved on a computer available to inmates in the center to access with their password.

According to the information the Government has provided to the unions, the Cybersecurity Agency’s report will take weeks to complete due to the technological complexity involved and the volume of information existing on the Generalitat’s network that was accessed, but they have detailed “what has been found to date.” Among the documents—dating from four or five years ago—accessed in the dozen folders, there are license plates of cars related to NIP (personal identification number; number of people to be determined). Also lists with data (name, ID number, and email) of staff who use a card for electronic signing at work (number and workplaces to be determined), lists with some corporate phone numbers of penitentiary center managers and volunteers. The administration has also assured them that work has been done on the network so that it currently has the highest level of security achievable so far and that “it is unlikely that an attack like the one suffered will happen again.”

Read more Scabies, tuberculosis, and impetigo cases in Ceuta: it is not the immigrants, it is the conditions in which they are forced to live

Justice has insisted that “the extent of the number of people who may be affected is still to be confirmed,” which will be known as the investigation progresses and that when it is known “they will contact all affected workers to inform them,” as required by data protection regulations. Department officials have also explained that they do not know if the information has left the computer on which it was copied, although they consider that “there is no indication that this has happened.”

Exercise in transparency

UGT demands that the Department be “absolutely transparent” and responsible towards workers who may see some personal data compromised. Also, that the necessary measures be applied to minimize any risk to anyone affected, and in this regard, we have proposed recovering the protected license plates for penitentiary workers’ vehicles, which they had years ago. The Government has taken up the proposal and committed to managing with the Ministry of the Interior to authorize their use by penitentiary officers. The union also demands that responsibilities be sought from the service provider “for any errors detected in the operation of the systems, especially when the investigation clearly shows negligence on their part.”

According to EL PAÍS, the three inmates identified as the authors of the cyberattack have been separated into different centers. None of them are incarcerated for committing cybercrimes, and they managed to breach the system’s security through the touchscreens used for video calls, which have been operational for just over a year. The system alarms went off, and an inmate tipped off what had happened.

Read more Images of the eviction from El Trampolín beach, where around 3,500 people were camping

Translated from

Leave a Reply

Your email address will not be published. Required fields are marked *