Verified cybersecurity incident and help-line context · Spain / INCIBE-CERT
INCIBE-CERT managed incidents and 017 consultations — Spain 2025
Market context — not industry-specific evidence
INCIBE-CERT managed 122,223 cybersecurity incidents in calendar year 2025, a 26% year-on-year increase, and proactively detected and notified 237,028 relevant vulnerable systems. Of the total incidents, 401 were attended among essential and important operators aligned with NIS2 terminology; within that operator subset, banking accounted for 34%, transport 14%, energy 8%, financial-market infrastructure 7%, and insurers and pension funds 6%. Across all managed incidents, malware accounted for 55,411 cases (including 392 ransomware attacks), online fraud for 45,445 cases, phishing for 25,133 cases, and information theft for 3,849 cases. 4,600 potentially fraudulent .es domains were closed in collaboration with Red.es. The INCIBE 017 help-line handled 142,767 consultations, a 44.9% year-on-year increase, of which 49% were preventive and 51% reactive. These figures are Spain INCIBE-CERT 2025 reporting context; they are not total Spanish business incident prevalence and not industry-specific evidence.
Cybersecurity incidents managed by INCIBE-CERT — 2025
- Cybersecurity incidents managed by INCIBE-CERT
- 122,223
- Unit
- cybersecurity incidents managed by INCIBE-CERT
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
INCIBE-CERT managed 122,223 cybersecurity incidents in calendar year 2025.
Spain INCIBE-CERT 2025 reporting context only. Not total Spanish business incident prevalence and not industry-specific evidence.
Year-on-year increase in INCIBE-CERT managed incidents — 2025
- Year-on-year increase in managed incidents
- 26%
- Unit
- percent year-on-year increase in managed incidents
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
INCIBE-CERT managed incidents increased 26% year-on-year in calendar year 2025.
Spain INCIBE-CERT 2025 reporting context only. The 26% is a year-on-year change in managed incident counts and does not measure a per-business incident rate. Not total Spanish business incident prevalence and not industry-specific evidence.
Relevant vulnerable systems proactively detected and notified — 2025
- Relevant vulnerable systems proactively detected and notified
- 237,028
- Unit
- relevant vulnerable systems proactively detected and notified by INCIBE-CERT
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
INCIBE-CERT proactively detected and notified 237,028 relevant vulnerable systems in calendar year 2025.
Spain INCIBE-CERT 2025 reporting context only. Not total Spanish business incident prevalence and not industry-specific evidence.
Incidents attended among essential and important operators — Spain 2025
- Incidents attended among essential and important operators (NIS2-aligned)
- 401
- Unit
- incidents attended among essential and important operators (NIS2-aligned, 2025)
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
401 incidents were attended among essential and important operators aligned with NIS2 terminology in 2025; a distinct subset of the 122,223 total managed incidents.
NIS2-aligned essential/important-operator incident subset only. This is not a count of all-Spain business incidents and not industry-specific evidence.
Key sectors affected within the 401 essential/important-operator incident subset — 2025
- Banking — 34%
- 34%
- Unit
- percent — banking share within the 401 essential/important-operator incident subset
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
- Transport — 14%
- 14%
- Unit
- percent — transport share within the 401 essential/important-operator incident subset
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
- Energy — 8%
- 8%
- Unit
- percent — energy share within the 401 essential/important-operator incident subset
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
- Financial-market infrastructure — 7%
- 7%
- Unit
- percent — financial-market infrastructure share within the 401 essential/important-operator incident subset
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
- Insurers and pension funds — 6%
- 6%
- Unit
- percent — insurers and pension-funds share within the 401 essential/important-operator incident subset
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
These percentages describe key sectors affected within the 401 essential/important-operator incident subset aligned with NIS2 terminology only. They are not all-Spain sector incident prevalence rates, all-business sector rates, or industry-specific evidence for any sector shown on this page.
Selected managed incident categories — Spain 2025
- Malware cases — 55,411
- 55,411
- Unit
- malware cases managed by INCIBE-CERT
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
- Ransomware attacks (within malware) — 392
- 392
- Unit
- ransomware attacks (subcategory within malware cases)
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
- Online fraud cases — 45,445
- 45,445
- Unit
- online fraud cases managed by INCIBE-CERT
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
- Phishing cases — 25,133
- 25,133
- Unit
- phishing cases managed by INCIBE-CERT
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
- Information-theft cases — 3,849
- 3,849
- Unit
- information-theft cases involving unauthorised access to or extraction of digital and/or confidential data
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
Source-defined incident categories within INCIBE-CERT 2025 managed incidents. The 392 ransomware figure is a subcategory within the 55,411 malware cases, not a separate peer count. These are not total Spanish business incident rates and not industry-specific evidence.
Potentially fraudulent .es domains closed — Spain 2025
- Potentially fraudulent .es domains closed in collaboration with Red.es
- 4,600
- Unit
- potentially fraudulent .es domains closed in collaboration with Red.es
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
4,600 potentially fraudulent .es domains were closed in collaboration with Red.es in calendar year 2025.
Proactive domain closure action by INCIBE in collaboration with Red.es. This is not a count of Spanish business cyber incidents and not industry-specific evidence.
INCIBE 017 help-line consultations handled — 2025
- INCIBE 017 consultations handled
- 142,767
- Unit
- INCIBE 017 help-line consultations handled
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
INCIBE 017 handled 142,767 consultations in calendar year 2025.
INCIBE 017 help-line context only. Not total Spanish business incident prevalence and not industry-specific evidence.
Year-on-year increase in INCIBE 017 consultations — 2025
- Year-on-year increase in consultations
- 44.9%
- Unit
- percent year-on-year increase in INCIBE 017 consultations
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
INCIBE 017 consultations increased 44.9% year-on-year in calendar year 2025.
INCIBE 017 help-line context only. The 44.9% is a year-on-year change in consultation counts and does not measure a per-person victimisation rate. Not total Spanish business incident prevalence and not industry-specific evidence.
Preventive consultations share — INCIBE 017 2025
- Preventive consultations
- 49%
- Unit
- percent of 017 consultations that were preventive
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
49% of INCIBE 017 consultations in calendar year 2025 were preventive.
INCIBE 017 help-line context only. Not total Spanish business incident prevalence and not industry-specific evidence.
Reactive consultations share — INCIBE 017 2025
- Reactive consultations
- 51%
- Unit
- percent of 017 consultations that were reactive
- Period
- Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
- Scope
- Spain INCIBE-CERT 2025 managed incident and 017 consultation context
51% of INCIBE 017 consultations in calendar year 2025 were reactive.
INCIBE 017 help-line context only. Not total Spanish business incident prevalence and not industry-specific evidence.
Source: INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026
Scope: INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026. The 122,223 managed incidents and 237,028 vulnerable-system notifications describe INCIBE-CERT 2025 reporting context. The 401 essential/important-operator incidents are a NIS2-aligned subset; the sector percentages (banking, transport, energy, financial-market infrastructure, insurers/pension funds) apply only to that 401-incident subset and must not be presented as all-Spain sector prevalence rates, all-business sector rates, or industry-specific evidence. The 392 ransomware attacks are a subcategory of the 55,411 malware cases. The 26% and 44.9% figures are year-on-year changes in counts and do not measure per-business or per-person incident rates. These figures do not measure total Spanish business incident prevalence, hidden incident prevalence, population-wide victimisation rates, industry-specific evidence, compliance achievement, certification or security outcomes.
Methodology: Official INCIBE press release and Balance de Ciberseguridad 2025 INCIBE (supporting PDF). The 122,223 managed incidents, 237,028 vulnerable systems notified, and 401 essential/important-operator incidents describe INCIBE-CERT 2025 reporting context. The 26% increase is a YOY change in managed incident counts; it does not measure a per-business incident rate. The 401 essential/important-operator incidents are aligned with NIS2 terminology; the sector percentages (34% banking, 14% transport, 8% energy, 7% financial-market infrastructure, 6% insurers/pension funds) describe key sectors affected within the 401-incident subset only and must not be presented as all-Spain sector incident prevalence, all-business sector prevalence, or industry-specific evidence. The 392 ransomware attacks are a subcategory within the 55,411 malware cases. The 44.9% increase in 017 consultations is a YOY change and does not measure per-person victimisation. These figures are Spain INCIBE-CERT 2025 reporting context only; they are not total Spanish business incident prevalence, hidden incident prevalence, population-wide victimisation rate, industry-specific evidence, compliance achievement, certification, or proof of security.
Accessible data table
| Metric | Value | Source | Scope | Reporting period |
|---|---|---|---|---|
| Cybersecurity incidents managed by INCIBE-CERT | 122,223 cybersecurity incidents managed by INCIBE-CERT | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Year-on-year increase in managed incidents | 26% percent year-on-year increase in managed incidents | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Relevant vulnerable systems proactively detected and notified | 237,028 relevant vulnerable systems proactively detected and notified by INCIBE-CERT | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Incidents attended among essential and important operators (NIS2-aligned) | 401 incidents attended among essential and important operators (NIS2-aligned, 2025) | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Banking — 34% | 34% percent — banking share within the 401 essential/important-operator incident subset | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Transport — 14% | 14% percent — transport share within the 401 essential/important-operator incident subset | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Energy — 8% | 8% percent — energy share within the 401 essential/important-operator incident subset | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Financial-market infrastructure — 7% | 7% percent — financial-market infrastructure share within the 401 essential/important-operator incident subset | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Insurers and pension funds — 6% | 6% percent — insurers and pension-funds share within the 401 essential/important-operator incident subset | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Malware cases — 55,411 | 55,411 malware cases managed by INCIBE-CERT | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Ransomware attacks (within malware) — 392 | 392 ransomware attacks (subcategory within malware cases) | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Online fraud cases — 45,445 | 45,445 online fraud cases managed by INCIBE-CERT | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Phishing cases — 25,133 | 25,133 phishing cases managed by INCIBE-CERT | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Information-theft cases — 3,849 | 3,849 information-theft cases involving unauthorised access to or extraction of digital and/or confidential data | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Potentially fraudulent .es domains closed in collaboration with Red.es | 4,600 potentially fraudulent .es domains closed in collaboration with Red.es | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| INCIBE 017 consultations handled | 142,767 INCIBE 017 help-line consultations handled | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Year-on-year increase in consultations | 44.9% percent year-on-year increase in INCIBE 017 consultations | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Preventive consultations | 49% percent of 017 consultations that were preventive | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
| Reactive consultations | 51% percent of 017 consultations that were reactive | INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026 | Spain INCIBE-CERT 2025 managed incident and 017 consultation context | Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context |
