Technology
Barcelona Emerges as Europe's Cybersecurity Hub Amid Rising Spanish Attacks
A dense network of firms and rising startup capital distinguish the city amid a surge in attacks across Spain and Catalonia.
How we reported this
Barcelona's cybersecurity sector features more than 550 companies that employ 10,600 professionals and generate an annual turnover of 1.473 billion euros, placing the city tenth among EU locations for startup funding in the field.
These numbers reflect a concentrated cluster that supports both defensive services and innovation at a time when reported incidents continue to climb. Spain recorded 122,223 cybersecurity incidents in 2025, a 26 percent increase from the prior year, according to data presented at the Barcelona Cybersecurity Congress. Phishing accounted for 25,133 of those cases, the leading attack vector. Barcelona City Council alone logged more than 25,000 incidents by May 2025, matching its full-year total from 2024 and driven mainly by phishing and DDoS activity tied to pro-Russian groups.
Threat patterns shape local priorities
The Catalan Cybersecurity Agency handled 3,372 incidents in 2024, up 26 percent from 2023, with most cases involving credential leaks and unauthorized email access. AI-supported phishing now makes up more than 80 percent of global social-engineering activity, a shift that has prompted firms in the Barcelona area to adjust detection tools and staff training. The combination of volume and specialization gives the local ecosystem a distinct profile compared with other European centers that lack comparable density of dedicated companies.
Figures from the sector show 18.4 percent growth in turnover during 2024, underscoring steady expansion even as attacks multiply. The 017 Cybersecurity Helpline fielded 142,767 inquiries that year, a 44.9 percent rise, indicating heightened public engagement with basic protections such as two-factor authentication already rolled out across city council systems.
Practical steps for organizations and residents
Companies can review credential-management practices and test phishing simulations that mirror the AI-enhanced campaigns now dominant. Individuals benefit from enabling available multi-factor tools and reporting suspicious messages through established channels like the 017 line. These measures align directly with the documented threat trends and the resources already present in the local market.