[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDohY-TH8yxmQxYuJW8LisF7FpteLvxy6LJyHTcgVu7Y":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"413e41a7-f3d8-4af7-880c-a3c4a69a2afa","spanish-hacker-uses-stolen-credentials-and-social-engineering-to-breach-government-networks","393f7fdb-8b3e-407c-96c3-908698a64b8a","Spanish Hacker Uses Stolen Credentials and Social Engineering to Breach Government Networks","José Luis Huertas exploited weak access controls by using a stolen digital certificate from Spain's traffic agency to breach critical government networks including SARA and the Neutral Judicial Point. He then created phishing pages to harvest court workers' credentials, demonstrating how social engineering can bypass technical security measures. This case highlights the devastating impact when privileged access credentials are compromised, allowing attackers to access sensitive banking records of over 500,000 citizens. The incident shows how attackers combine technical exploitation with human manipulation to maximize their access to valuable data.","**Immediate actions:**\n- Implement multi-factor authentication for all privileged accounts and system access\n- Conduct emergency security awareness training focused on phishing recognition for all staff\n- Review and revoke unnecessary digital certificates and privileged access permissions\n\n**Long-term improvements:**\n- Deploy certificate management systems with automated monitoring and anomaly detection\n- Establish role-based access controls with regular access reviews and least privilege principles\n- Create network segmentation between different government systems and agencies\n\n**Detection measures:**\n- Implement real-time monitoring for suspicious certificate usage and credential access patterns\n- Deploy email security solutions with advanced phishing detection and user reporting capabilities",[12,13,14,15,16,17],"CIS Control 5 (Account Management)","CIS Control 14 (Security Awareness and Training)","NIST AC-2 (Account Management)","NIST AC-6 (Least Privilege)","NIST IA-5 (Authenticator Management)","GDPR Article 32 (Security of Processing)","published","2026-06-03T12:07:01.896787+00:00","2026-06-03T12:07:01.603+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fhackread.com\u002Falcasec-robin-hood-of-spanish-hackers-jail-data-theft\u002F","alcasec-robin-hood-of-spanish-hackers-jailed-for-31-months-over-data-theft-a63502","Alcasec, “Robin Hood of Spanish Hackers,” Jailed for 31 Months Over Data Theft",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]