Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
When ransomware crippled Universitat Autònoma de Barcelona (UAB) in October 2021, the public university faced a continuity crisis affecting about 1,200 servers, 10,000 computers and more than 50,000 users. It did not pay the attackers. Recovery took roughly three months—not because backups were absent, but because the university had to determine which copies were safe and rebuild critical systems without carrying a hidden compromise back into service.
The case offers a practical lesson for public institutions and other organizations: resilience depends on tested recovery, independent communications and clear authority as much as on security tools.
What happened at UAB
The victim was the Universitat Autònoma de Barcelona, a public university in Spain—not the University of Alabama at Birmingham. The attack unfolded over the long weekend around Spain’s October 12 National Day in 2021. Spanish coverage identifies October 11 as the initial incident date.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
UAB CIO Gonçal Badenes said the university believed an attacker obtained credentials belonging to a student or other low-privilege user, probably through phishing. That remains a suspected entry path, not a proven account of exactly how the attackers got in; Badenes also said the user was not at fault.
#1 Best Overall
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
The PYSA ransomware attack hit the university’s data-processing environment, including its VMware virtualization repository and a backup environment. A separate PowerShell script encrypted active user computers connected to campus systems. The result was a broad outage, not simply a set of isolated infected laptops. CSO Online’s account of Badenes’s experience describes the scope and response.
UAB’s forensic review reportedly found its corporate databases unaffected and assessed the amount of potentially leaked information as very limited. That is the university’s assessment; it should not be restated as proof that no data was exfiltrated. File encryption and data theft are separate questions, and a victim needs to investigate both.
Why one compromised account could become a university-wide crisis
Universities combine large, changing populations—students, faculty, researchers, contractors and visitors—with a wide range of devices and systems. Some endpoints are centrally managed; others may be less consistently inventoried or maintained. Essential services such as identity, learning platforms, email, research systems and administrative applications depend on interconnected infrastructure. Decentralized IT ownership and older systems can make it harder to apply uniform controls.
That combination creates pressure to keep services running while complicating containment. A low-privilege account should not be able to reach critical infrastructure, but a compromised credential can still be a foothold if identity boundaries, endpoint controls and network segmentation do not limit where an attacker can go. The case does not establish that phishing alone explains the attack’s full path.
Preparation helped, but it could not make the outage painless
UAB had a ransomware response plan aligned with Spain’s National Security Scheme, a security committee and an established response methodology. It also had a continuity or detection system that raised alerts as systems began failing, multiple backup copies—including tape—and an external company it could call for assistance. The university had existing relationships with public authorities and technology partners.
Rank #2
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Those arrangements helped the university organize a response. Badenes has compared cybersecurity preparation to a fire drill: a plan matters most when people know how to use it under pressure. A document stored only on a network that may be shut down is not an operational plan. Nor does a list of partners help much if no one knows who can authorize their involvement, share evidence or approve emergency work.
The first hours: contain, coordinate and communicate
As systems failed, UAB alerted Badenes and its internal security committee, moved toward disconnecting or shutting down systems to limit further spread, and brought in outside partners and public authorities. The university then had to assess the scope and likely attack path, determine which systems and backup copies could be trusted, and decide what to rebuild.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Isolation can slow active encryption and lateral movement, but it also cuts off services people rely on. Before an incident, organizations should decide who has authority to isolate a network, what criteria trigger that action, which essential services need explicit exceptions, and how safety and operations will continue offline. Waiting for broad executive consensus while encryption is spreading can make damage worse; isolating everything without continuity plans can create a different emergency.
UAB also found that normal university communications were unavailable. It set up a temporary WordPress site hosted externally and a public Telegram channel. The lesson is to prepare an out-of-band channel in advance, not improvise the whole communications system during the outage. A workable plan needs separately controlled hosting and identity, offline contact lists, prewritten status and safety updates, and a fast approval process. It should reach staff, students, suppliers, regulators, law enforcement and media while distinguishing confirmed facts from early hypotheses. A known, authenticated channel also helps people recognize impersonation and misinformation.
Badenes’s account points to a governance issue as well: internal procedures can be too slow when decisions must be made immediately. A response plan should identify an incident commander and define delegated authority, rather than leaving urgent containment and communications decisions to an ad hoc group.
Rank #3
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Backups: having copies was not the same as being ready to recover
The attack encrypted a main data repository and a backup environment. UAB initially believed its first and second backup copies had been destroyed. After about 10 days, the university discovered its tape copy was safe; Dell Technologies also reportedly determined that the second backup was recoverable.
Free tools Windows power users keep installed
One-click scans. No signup required.
This is more instructive than a simple claim that “backups saved the day.” A copy can exist but be inaccessible during an attack, corrupted, incomplete, untrusted or too slow to restore. Even a clean data copy may not be enough if the organization lacks configuration files, encryption keys, application dependencies or a safe path to rebuild identity and virtualization.
- Existence: Is there a recent copy of the data and configuration?
- Isolation: Can production credentials or compromised systems alter or erase it?
- Integrity: Is the copy complete and free of corruption or malicious changes?
- Recoverability: Can teams restore the service and its dependencies, not merely retrieve files?
- Trust: Can the organization establish that restored systems do not contain attacker persistence or compromised settings?
- Speed: Can recovery meet documented business needs?
UAB’s reported multiple copies, including tape, support the value of layered backup. They do not establish that the university formally followed a specific 3-2-1 strategy or used immutable backups. For any organization, the practical goal is at least one recovery copy isolated from the production identity and administrative plane, with separate credentials and regular restoration exercises. A “successful” backup job is not evidence of a successful recovery until teams have tested it.
Why UAB rebuilt core systems instead of rushing to restore them
Badenes said ransomware can leave backdoors or malicious configurations behind. UAB therefore rebuilt critical infrastructure from scratch, including backup infrastructure, identity systems, databases and virtualization systems, and applied updates before loading data back in.
A rapid restore can shorten an outage but risks bringing compromised machines, credentials or configurations back online. A clean rebuild offers greater confidence but takes more time and effort. The right choice depends on the system’s importance, the evidence available and the ability to validate a restored environment.
Rank #4
- DEVICE SECURITY - Award-winning McAfee antivirus, real-time threat protection, protects your data, phones, laptops, and tablets
- SCAM DETECTOR - We'll automatically identify risky texts, emails, and videos that attempt to steal your personal or financial information. You can even use our mobile app to check social messages and QR codes for scams on-demand, without missing a beat.
- SECURE VPN – Secure and private browsing, unlimited VPN, privacy on public Wi-Fi, protects your personal info, fast and reliable connections
- IDENTITY MONITORING – 24/7 monitoring and alerts, monitors the dark web, scans up to 60 types of personal and financial info
- SAFE BROWSING – Guides you away from risky links, blocks phishing and risky sites, protects your devices from malware
A practical middle path is a staged recovery: restore low-risk services quickly where trust can be established, while rebuilding identity, backup management, virtualization and other foundational systems in a clean environment with stricter controls. Recovery plans should rank services by business impact and map their dependencies. Identity, DNS, certificates, network management and virtualization may need to be restored before the applications employees and students are waiting for.
Why the university did not pay
Badenes said UAB neither paid nor contacted the attackers. He cited ethical and legal considerations and the university’s status as a public entity. Its procurement rules also required a public tender for expenses above €15,000. Press reports later put the attackers’ demand at about €3 million, reportedly roughly 1% of the university’s budget; Badenes said he had not inspected the ransom note and learned the figure from the press.
That decision should not be turned into universal legal advice to pay or never pay. Organizations facing an extortion demand need to consider applicable sanctions and legal exposure, whether data was stolen, whether backups are usable, the safety and continuity consequences of downtime, the credibility of any promised decryption tool, and advice from law enforcement, insurers and incident responders. Public bodies also need to account for procurement, public accountability and emergency-spending rules. Payment is not a guarantee of recovery, and it does not by itself remove an attacker’s access or settle questions about data exposure.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Recovery took longer than the initial outage
The university’s first services returned after about 15 days. Critical services came back roughly two weeks later, while the complete recovery effort—including smaller remaining issues—took approximately three months. The timeline below is approximate because the published accounts give elapsed periods rather than a full incident log.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors| Approximate point | What the account reports |
|---|---|
| Day 0 | Systems begin failing; UAB activates its response and containment work. |
| Around day 10 | The university identifies a safe tape backup; Dell reportedly finds the second backup recoverable. |
| Around day 15 | First services are restored. |
| About one month | Critical services are restored, around two weeks after the first services return. |
| About three months | Remaining recovery work is completed. |
“Systems were down for about two weeks” and “recovery took about three months” describe different milestones. Treating them as contradictory obscures the work of rebuilding, validating and restoring services in a safe order.
Best Value
- World’s First 6TB 2.5” Portable Hard Drive
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
What changed afterward—and what other institutions can take from it
UAB later expanded multifactor authentication across services, including VPN access that had not previously been covered universally. It replaced obsolete end-user equipment, centralized endpoint management that had been decentralized, added layered controls using different technologies and locations, and established a dedicated CISO role. Badenes had been acting as both CIO and de facto CISO during the attack. The account underscores why security ownership should be explicit rather than an extra duty assumed during a crisis.
MFA is important, but it is not a complete ransomware defense and the evidence does not show that MFA alone would have prevented this attack. Coverage should include VPN and other remote access, privileged operations and relevant service accounts. Phishing-resistant MFA, privileged-access controls, endpoint detection, segmentation, patching and monitoring address different ways attackers may gain or expand access.
For a university, public agency or other organization, UAB’s experience suggests a focused preparation checklist:
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →- Practice containment: name the incident commander, define isolation authority and test continuity for services that lose network access.
- Prove recovery: conduct realistic restores of critical services, including identity, virtualization and backup management, in an isolated environment.
- Separate administration: protect backup and identity systems with distinct access controls and recovery paths; keep at least one copy offline or otherwise isolated.
- Know the estate: maintain endpoint inventories, centralize management, patch obsolete systems and ensure security monitoring covers the devices that matter.
- Prearrange help: identify incident responders, public authorities, legal counsel, insurers and technology suppliers before an incident, with contact and evidence-sharing processes ready.
- Prepare communications: maintain an externally hosted, independently authenticated status channel, offline contact lists and templates that can be approved quickly.
- Resolve payment governance early: document who assesses legal, sanctions, procurement, insurance and continuity issues so those questions do not first arise during an outage.
- Set recovery priorities: rank services by operational impact and map the infrastructure each depends on; rehearse the sequence, not just the backup restoration.
UAB’s recovery did not rest on a single product or a single lucky copy of data. It combined prior planning, multiple backup layers, external coordination, temporary communications and a deliberate decision to rebuild foundational systems cleanly. The lasting lesson is to make those capabilities executable before the network goes dark.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

