Overview
- Prison staff at Puig de les Basses in Girona discovered the unauthorized access and reported it to the Department of Justice on Wednesday, prompting an immediate investigation.
- Justice officials said initial checks found no breach of critical prison systems and that the suspected inmates have been identified.
- The incident was formally notified to the Figueres court and the Catalan Data Protection Authority while the Agencia de Ciberseguridad de Catalunya began an exhaustive technical analysis to map how access occurred and its scope.
- The union SICAP-Fepol says prisoners used available computers to view confidential files including health data and demands an independent external audit, forensic custody of affected devices, revocation of compromised credentials, and network isolation for inmate terminals.
- Authorities have tightened firewalls and other protections across Catalan prisons and could face wider audits, notifications to affected people, and policy changes for how inmate-accessible equipment is configured and monitored.