Security Breach Alleged at Catalan Prisons

SICAP-FEPOL, a prison staff trade union, has filed a formal complaint alleging a serious cybersecurity breach in Catalan prisons, claiming that inmates may have accessed non-public data belonging to the Generalitat from computers inside prison modules. The union said it has gathered evidence indicating that unauthorised individuals in custody accessed internal government environments and repositories, potentially exposing personal data, health records, and penitentiary information. The union described the incident as "extremely serious" and warned that the separation between inmate-accessible computers and internal government systems had failed. According to SICAP-FEPOL, the exposed data includes highly protected health information. The union stated that both inmates and prison staff had raised concerns about unauthorised access and technical misconfigurations as early as 2025, raising questions about whether officials acted promptly.

Demands for Accountability and Investigation

SICAP-FEPOL is demanding that the Catalan government clarify when the breach began, how many prisons were affected, which files were accessed, and how many individuals may be at risk. The union also wants to know whether any data was downloaded or disseminated. The union has announced it will file a complaint with the Catalan Data Protection Authority (APDCAT) and has called on the Department of Justice to activate its incident response protocol immediately. It demands the preservation of digital evidence, the temporary disconnection of affected equipment, and an external technical audit of prison networks, permissions, and credentials. SICAP-FEPOL is also calling for the immediate dismissal of Domingo Estepa Camacho, the Director General of Penitentiary Affairs, citing the severity of the alleged breach and prior warnings. The union insists that an independent investigation commission, including external cybersecurity and data protection experts, be established. The union argues that digitalisation and rehabilitation should not come at the expense of security, and warns that unauthorised access to sensitive data could lead to blackmail, impersonation, or threats to prison safety.


Separate reports confirm that inmates at Puig de les Basses prison in Figueres accessed shared network drives from non-secure computers, prompting an internal alert and investigation by the Department of Justice [Julio Collado]. The department stated that critical penitentiary systems were not compromised. Another case involves a known leader of the neo-Nazi group 'Deport Them Now', imprisoned at Quatre Camins, who allegedly accessed confidential databases while working under a prison labour scheme [GIRONA NOTÍCIES]. The data reportedly included personal information on vulnerable minors of Maghrebi origin and prison staff, prompting SICAP-FEPOL to warn of an "unacceptable security breach". The union has previously filed complaints against prison directors for alleged misuse of surveillance systems and public resources [sicap.cat], indicating ongoing concerns about governance and oversight.

If an inmate can access confidential Generalitat data from a prison computer, the security system has failed at its core.

SICAP-FEPOL has called for full transparency, stating that it wants to know what happened, who knew, when they knew it, why action wasn’t taken earlier, and which data may have been compromised.


Primary sources: govern.cat. Reported by Julio Collado, sicap.cat, gironanoticies.com, GIRONA NOTÍCIES, Miriam Saint-Germain, aldia.cat, Montse Rodríguez, VilaWeb.