Collado Villalba Restores Systems After Cyberattack Without Paying Ransom

The City Council successfully recovered 100% of its IT infrastructure in five days thanks to intensive work by the technical team.

Generic image of computer servers with blinking lights.
IA

Generic image of computer servers with blinking lights.

The Collado Villalba City Council has fully restored its IT infrastructure in just five days following a cyberattack, without paying any ransom and with no data loss.

The Collado Villalba City Council has regained operational normality after a cyberattack suffered on September 15th. In a record time of five days, 100 percent of the Council's IT infrastructure has been restored, as confirmed by the Councilor for Digitalization, Miguel Aisa. This achievement was accomplished without paying any ransom and with no data loss.
Mayor Mariola Vargas assured that no payment was made for the ransom, citing the lack of guarantees for data recovery. The police investigation, which is under judicial secrecy, prevents the disclosure of the amount requested by the attackers.
Municipal technicians, personnel from the Cybersecurity Agency of the Community of Madrid, and the external IT support company worked intensively during shifts exceeding 16 hours to review over 6 terabytes of the City Council's information.
Since Monday morning, the Electronic Office is once again fully operational, allowing citizens to carry out telematic procedures from home. Additionally, normal functioning has resumed in other areas of the City Council.
Miguel Aisa described the restoration as "unprecedented for a local administration," highlighting the robustness of security protocols and the quality of the technical team. Mayor Mariola Vargas praised the municipality's "magnificent response and resilience," the "exemplary civic-mindedness and understanding" of residents, and the collaboration of the Department of Digitalization, the Regional Ministry of Digitalization, the Guardia Civil, and other public-private entities.
The municipal head of IT, Óscar López, revealed that the City Council faces approximately 3,000 cyberattacks annually, although implemented security systems prevent most of them. Recently, the Plenary approved allocating 250,000 euros from Treasury reserves to enhance these systems, with further funding planned to increase security.
The Guardia Civil, the National Cryptologic Center (CNN), and the Cybersecurity Agency of the Community of Madrid are investigating the attack's origin, suspected to be an expert individual or organization. The modus operandi and standard messages align with patterns seen in similar attacks occurring simultaneously worldwide.
The digital intrusion reportedly began through a vulnerability in the IT support of one of the City Council's external providers. Unlike other incidents, no data leak has been detected on the 'Dark Web'.
The attack was detected in the early hours of Tuesday, September 15th. After activating security protocols, a team of 15 people was assembled, including municipal staff, external company personnel, and the Security Agency. The network was isolated to prevent further damage, and by Saturday morning, all information had been recovered, with systems cleaned and analyzed.
Redundancy and containment systems prevented greater damage, unlike recent incidents in municipalities such as Velilla de San Antonio or Valdemoro. Miguel Aisa detailed the "surgical" work to audit each server, remove entry traces, and reinforce environments with new security layers, resulting in a more robust digital infrastructure.
The City Council anticipates potential system saturation at the Citizen Service Centers (SAC) and web portals due to the backlog of procedures. The public is asked for patience, as high user concurrency may temporarily slow down response and processing times. Administrative deadlines affected by the incident have been extended.