Banking Law And Hybrid Warfare Spain .
Banking Law and Hybrid Warfare in Spain
1. Introduction
Hybrid warfare describes the coordinated use of multiple instruments—cyber operations, economic pressure, disinformation, espionage, political interference, criminal activity and, where applicable, conventional military force—to pursue strategic objectives without relying exclusively on open armed conflict.
For banking law, the important point is that a modern banking system can itself become part of the critical infrastructure and economic-security environment. A hostile operation against banks, payment systems, financial-market infrastructure or confidence in the financial system can create effects beyond an ordinary cybercrime incident.
Spain's National Security Strategy 2021 expressly identifies the increasing use of hybrid strategies and places preparation against such strategies within national-security planning. Spain's national-security framework also separately identifies threats involving critical infrastructure, cyber-space, foreign interference and economic/financial instability.
For banking regulation, the framework is therefore not contained in one "Hybrid Warfare Banking Act." Instead, it results from the interaction of:
- Spanish banking legislation;
- EU banking law;
- prudential supervision;
- cybersecurity and operational-resilience rules;
- sanctions and financial restrictions;
- anti-money-laundering law;
- national-security law;
- criminal law;
- payment-system regulation.
2. Meaning of Hybrid Warfare in the Banking Context
A simplified model is:
State or state-linked actor
↓
Cyberattack / espionage / disinformation / economic pressure
↓
Bank or financial infrastructure
↓
Payment disruption / data theft / market instability / loss of confidence
↓
Economic and national-security consequences
Thus, hybrid warfare can affect banking through several channels.
| Hybrid instrument | Possible banking effect |
|---|---|
| Cyberattack | Disruption of banking systems |
| Cyberespionage | Theft of customer or strategic information |
| Ransomware | Operational shutdown |
| Disinformation | Bank runs or loss of confidence |
| Economic coercion | Pressure on financial institutions |
| Sanctions evasion | Use of banks to circumvent restrictions |
| Market manipulation | Artificial volatility |
| Foreign interference | Attempts to influence financial institutions |
| Supply-chain attack | Compromise of outsourced IT providers |
| Criminal networks | Money laundering and illicit financing |
3. Spanish National-Security Framework
Spain's Law 36/2015 on National Security provides the principal national-security framework.
The National Security Strategy is the principal reference framework for Spanish national-security policy. The 2021 Strategy specifically responded to a changing security environment and the increased use of hybrid strategies.
This is important because banking disruption can become a national-security issue when it affects:
- financial stability;
- essential services;
- critical infrastructure;
- economic activity;
- public confidence;
- national sovereignty.
The Spanish National Security Strategy also recognizes cyberespionage and hostile intelligence activities as potential components of hybrid strategies.
4. Banking Regulation in Spain
Spanish banking regulation operates through a combination of Spanish and EU law.
Important institutions include:
Banco de España
Responsible for important aspects of banking supervision and payment-system oversight.
European Central Bank
Directly supervises significant banks under the Single Supervisory Mechanism (SSM).
CNMV
Regulates securities and capital-market activities.
Ministry of Economy
Participates in the broader financial regulatory framework.
National Security Department
Coordinates elements of Spain's national-security policy.
This institutional structure is important during hybrid threats because a serious attack can simultaneously create:
- a banking-supervision problem;
- a cybersecurity problem;
- a criminal-law problem;
- a national-security problem.
5. Cybersecurity as Banking Law
Cybersecurity is no longer merely an internal IT issue for Spanish banks.
The EU Digital Operational Resilience Act (DORA) has become a central component of financial-sector operational resilience.
DORA establishes requirements concerning:
- ICT risk management;
- incident reporting;
- resilience testing;
- third-party ICT risk;
- governance;
- information sharing.
Banco de España now provides a mechanism for financial institutions to report serious ICT incidents, serious payment-related operational/security incidents and significant cyber threats under DORA.
Thus, if a bank is attacked during a hybrid operation, the incident can trigger formal regulatory obligations rather than merely an internal security response.
6. Cyber-Resilience and Payment Systems
Payment infrastructure is particularly important.
Banco de España identifies cyber risks as one of the principal threats to the continuity of payment systems and financial-market infrastructures. Spain also participates in TIBER-ES, which uses threat-led penetration testing to simulate sophisticated attacks against financial institutions.
The legal objective is therefore not merely:
"Stop hackers."
It is:
Ensure that the financial system can continue functioning even when sophisticated hostile actors attack it.
7. Hybrid Warfare and Systemic Risk
Hybrid attacks can become systemic when one institution's failure affects other financial institutions.
For example:
Cyberattack on Bank A
↓
Payment-processing failure
↓
Bank B cannot receive settlement
↓
Corporate customers cannot make payments
↓
Liquidity stress
↓
Market confidence deteriorates
↓
Potential systemic instability
This is why prudential regulation is relevant to hybrid warfare.
Banco de España's recent financial-stability work identifies geopolitical tensions as a source of financial risk and continues to assess the resilience of Spanish banks against adverse scenarios.
8. Capital and Liquidity as Defence Mechanisms
Traditional banking regulation can indirectly contribute to national resilience.
Banks maintain:
- capital buffers;
- liquidity reserves;
- risk-management systems;
- contingency arrangements;
- recovery plans;
- business continuity arrangements.
These mechanisms are normally described as prudential regulation, rather than "warfare regulation."
However, they become particularly important during a hybrid attack.
A bank with sufficient liquidity and operational redundancy can continue serving customers despite temporary disruption.
9. Sanctions and Financial Warfare
Hybrid warfare can also involve economic and financial measures.
Sanctions may restrict:
- individuals;
- companies;
- banks;
- transactions;
- assets;
- trade;
- financial services.
Spanish financial institutions therefore need systems capable of identifying restricted persons and transactions.
This creates a connection between:
Banking law + AML/CFT + sanctions compliance + national security.
Spain's financial system is also affected by EU sanctions regimes, which are legally important for banks operating in Spain.
10. Banking Secrecy and National Security
Banking institutions hold enormous quantities of sensitive information.
This includes:
- account information;
- transaction records;
- customer identity;
- corporate ownership;
- payment relationships;
- international transfers.
During a hybrid conflict, such information can become strategically valuable.
Therefore, cybersecurity must protect not only money, but also financial intelligence.
A successful espionage operation could reveal:
- strategic companies' financial positions;
- government-related transactions;
- defence-industry relationships;
- critical infrastructure payments;
- vulnerabilities in supply chains.
11. AML/CFT and Hybrid Threats
Money laundering and terrorist financing controls have an additional security dimension.
A hostile actor could attempt to use:
- shell companies;
- offshore accounts;
- cryptocurrencies;
- trade transactions;
- intermediaries;
- front companies.
to finance operations or conceal the origin of funds.
Spanish banks therefore operate within AML/CFT rules requiring risk-based customer and transaction controls.
This means that financial transparency becomes part of national resilience.
12. Disinformation and Bank Runs
Hybrid warfare does not necessarily require a technical attack.
Imagine a false online campaign claiming:
"Bank X has become insolvent."
Customers begin withdrawing money.
↓
Liquidity pressure increases.
↓
Other customers become concerned.
↓
The rumour spreads.
↓
A self-reinforcing bank run develops.
This demonstrates why financial stability depends partly on public confidence.
A false information campaign can therefore produce real financial consequences even if the underlying bank is financially sound.
13. Foreign Interference
Spain's national-security framework recognizes foreign interference and espionage as security concerns.
The National Security Strategy notes that hostile intelligence activity and cyberespionage can form part of broader hybrid strategies.
For banks, potential targets include:
- senior management;
- strategic financial data;
- government-related accounts;
- payment infrastructure;
- merger and acquisition information;
- defence-sector clients.
14. Third-Party Technology Risk
Modern banks rely heavily on:
- cloud providers;
- payment processors;
- cybersecurity companies;
- software providers;
- telecommunications providers.
A hybrid attacker could therefore attack the bank's supplier instead of the bank itself.
This is why DORA's treatment of ICT third-party risk is important.
The regulatory question becomes:
If a bank outsources its technology, does outsourcing transfer the bank's responsibility?
The answer under modern operational-resilience regulation is essentially no.
The regulated institution remains responsible for managing the risks associated with critical ICT dependencies.
15. Critical Infrastructure
The banking sector intersects with Spain's critical-infrastructure framework because financial services depend on interconnected systems.
Important infrastructure includes:
- payment systems;
- clearing systems;
- settlement infrastructure;
- telecommunications;
- electricity;
- data centres.
A hybrid attack may therefore begin outside the bank.
For example:
Electricity disruption
→ data-centre failure
→ banking-service interruption
→ payment-system disruption.
Consequently, resilience requires cross-sector coordination.
16. Case Law
There is an important methodological point here:
Spanish courts have relatively few reported decisions expressly titled or decided as "hybrid warfare banking cases."
Therefore, relevant case law must be drawn from cases involving the underlying legal components of hybrid financial attacks, particularly:
- cybercrime;
- banking fraud;
- unauthorized transactions;
- financial-sector cybersecurity;
- criminal attacks on financial institutions.
The following cases/decisions are useful for understanding those principles.
17. Case 1 — Audiencia Nacional: ATM Cyberattack
In 2021, the Spanish Audiencia Nacional convicted a Russian hacker who had infected computers of banking entities in different countries and remotely manipulated ATMs.
According to the Spanish judiciary, the operation produced almost €5 million in illicit withdrawals.
The defendant received a sentence involving:
- computer fraud;
- participation in a criminal organization;
- document forgery;
- money laundering.
Legal significance
This case demonstrates how cybercrime can directly attack the operational infrastructure of banks.
Hybrid-warfare relevance
Although the case was prosecuted as criminal conduct rather than formally as "hybrid warfare," the technique illustrates one component that could be incorporated into a larger hybrid operation:
malware → banking infrastructure → ATM manipulation → financial loss.
18. Case 2 — Spanish Banking Smishing Decision, 2025
In July 2025, the Tribunal de Instancia de Guadix No. 2 ordered a banking institution to reimburse money lost by a customer following an SMS-phishing ("smishing") attack.
The court considered the bank's cybersecurity measures and concluded that inadequate cybersecurity had contributed to the fraudulent transactions. The Spanish judiciary's account states that the judgment considered cybersecurity measures in light of DORA.
Importance
This case is particularly significant because it connects:
cybersecurity → banking responsibility → customer protection.
Hybrid-warfare relevance
A sophisticated hybrid operation can use phishing or social engineering as the first stage of an attack.
The case demonstrates why banks must protect customers against technologically enabled financial fraud rather than treating the problem entirely as customer misconduct.
19. Case 3 — Banco Popular Resolution Litigation
The resolution of Banco Popular Español in 2017 generated extensive litigation before Spanish and EU courts.
The bank was placed into resolution and subsequently sold to Banco Santander for €1.
The litigation concerned issues including:
- resolution;
- shareholder and bondholder rights;
- valuation;
- legality of the resolution process.
Relevance to hybrid warfare
This is not a hybrid-warfare case.
Its relevance is systemic resilience.
It demonstrates how European banking law provides mechanisms for dealing with a bank whose failure could threaten financial stability.
That same resolution infrastructure could become important if a bank suffers severe financial consequences from a large-scale hostile cyber or economic operation.
20. Case 4 — Tercas / Deposit Guarantee and Banking Resolution Jurisprudence
The European litigation surrounding Banca Tercas concerned state aid, deposit protection and banking intervention.
Although it involved an Italian bank rather than a Spanish one, it is relevant to Spanish banking law because Spanish banks operate within the EU banking framework.
The broader principle is that banking intervention must comply with:
- EU state-aid rules;
- banking-resolution rules;
- institutional competence;
- proportionality requirements.
Hybrid-warfare relevance
If a financial institution suffers major losses from a hostile economic or cyber operation, government assistance and resolution measures must still operate within applicable EU legal constraints.
21. Case 5 — Ledra Advertising v European Commission and ECB
Ledra Advertising Ltd v European Commission and ECB, Court of Justice of the European Union, 2016, concerned the Cyprus financial crisis and the involvement of EU institutions in financial-assistance measures.
The case examined the legal responsibility of EU institutions in the context of financial-sector crisis measures.
Importance
It illustrates the relationship between:
- financial stability;
- emergency economic measures;
- institutional responsibility;
- fundamental rights.
Spanish relevance
The case helps explain the broader European legal environment within which Spanish banking crisis measures operate.
22. Case 6 — Kotnik and Others v Slovenia
Kotnik and Others v Slovenia, CJEU, 2016, concerned banking restructuring and the compatibility of measures affecting subordinated bank creditors with EU law.
The judgment examined the legal framework surrounding burden-sharing in bank restructuring.
Relevance
In a severe banking crisis caused or aggravated by external economic pressure, governments may need restructuring tools.
But such interventions must remain within the boundaries established by EU law.
23. Case 7 — NLB Banka and Banking Resolution Jurisprudence
European banking-resolution cases involving the treatment of creditors demonstrate another principle important for Spain:
Financial stability measures must be legally structured and procedurally justified even during a crisis.
This is important for hybrid threats because an attack could create a rapidly developing crisis requiring emergency regulatory intervention.
24. Case-Law Summary
| Case | Court/Jurisdiction | Core issue | Relevance |
|---|---|---|---|
| ATM cyberattack case | Audiencia Nacional, Spain | Malware and ATM manipulation | Cyberattack against financial infrastructure |
| Guadix smishing case | Spanish court, 2025 | Bank cybersecurity and unauthorized transactions | Customer protection and cyber-responsibility |
| Banco Popular litigation | EU/Spain | Bank resolution | Systemic banking resilience |
| Tercas litigation | CJEU/EU | Bank intervention/state aid | Crisis-management powers |
| Ledra Advertising | CJEU | Financial crisis measures | Financial stability and institutional responsibility |
| Kotnik | CJEU | Bank restructuring | Crisis intervention and creditor rights |
| Other EU banking-resolution jurisprudence | CJEU | Resolution and systemic stability | Legal framework for severe banking crises |
The first two are directly connected to cyber-enabled banking incidents; the remaining cases are comparative banking-crisis authorities, not decisions declaring that a particular event constituted hybrid warfare.
25. Relationship Between Hybrid Warfare and DORA
DORA is particularly important because it changes the legal conception of cybersecurity.
Previously, cybersecurity was often treated primarily as:
IT risk
Modern financial regulation increasingly treats it as:
operational and prudential risk
Under DORA, serious ICT incidents must be reported through prescribed regulatory procedures. Banco de España's current reporting mechanism explicitly covers serious ICT incidents and important cyber threats.
This is highly relevant to hybrid warfare because sophisticated hostile operations frequently begin with cyber disruption.
26. TIBER-ES and Threat-Led Testing
Spain's TIBER-ES framework is another important component.
It uses advanced penetration testing designed to simulate the tactics, techniques and procedures of sophisticated real-world attackers. Banco de España describes these tests as an instrument for strengthening financial-sector cyber resilience.
This moves regulation from:
"Respond after attack"
toward:
"Test whether the institution can survive an attack before it occurs."
27. Banking Governance Responsibilities
Bank directors and senior management increasingly have responsibilities relating to:
- cyber-risk governance;
- operational resilience;
- incident response;
- outsourcing risk;
- business continuity;
- crisis management.
A hybrid attack therefore raises corporate-governance questions:
- Did management identify the risk?
- Were appropriate controls implemented?
- Was the incident detected promptly?
- Was the regulator notified?
- Were customers protected?
- Could essential banking services continue?
28. Criminal Law Dimension
Hybrid attacks against banks can involve several criminal offences, depending on the facts:
- computer fraud;
- unauthorized access;
- damage to computer systems;
- identity theft;
- money laundering;
- participation in criminal organizations;
- document fraud;
- theft;
- terrorism-related offences where legally applicable.
The Audiencia Nacional ATM case demonstrates that sophisticated cyberattacks can generate several overlapping criminal charges.
29. Economic Warfare
Hybrid warfare can also be conducted through economic pressure rather than direct cyberattack.
Potential methods include:
- manipulation of financial flows;
- sanctions evasion;
- market interference;
- attacks on investor confidence;
- disruption of cross-border payments;
- pressure on strategic companies.
Spanish banks therefore need both cyber resilience and financial-risk resilience.
Banco de España has specifically analysed geopolitical tensions and their possible effects on Spanish financial stability.
30. Difference Between Ordinary Cybercrime and Hybrid Warfare
| Ordinary cybercrime | Hybrid warfare |
|---|---|
| Usually criminal objective | Strategic/political objective may be involved |
| Often targets individuals or companies | May target critical sectors |
| Financial gain frequently central | Disruption or coercion may be central |
| Limited scope | Potentially systemic |
| Primarily criminal-law response | Criminal + regulatory + national-security response |
| Individual bank may be target | Financial system may be target |
The distinction depends on purpose, attribution, scale and context.
A ransomware incident against a bank is not automatically hybrid warfare.
It may become part of a hybrid campaign when combined with other coordinated activities pursuing a strategic objective.
31. Hypothetical Spanish Hybrid Banking Attack
Consider:
Stage 1: Foreign actor compromises a bank's supplier.
Stage 2: Malware enters the bank's infrastructure.
Stage 3: Payment processing becomes unavailable.
Stage 4: False social-media reports claim several Spanish banks are insolvent.
Stage 5: Customers begin withdrawing deposits.
Stage 6: Liquidity pressure increases.
Stage 7: The attacker releases stolen customer data.
Stage 8: International investors become concerned.
This single campaign could simultaneously engage:
- DORA;
- banking supervision;
- criminal law;
- data protection;
- national security;
- crisis-management mechanisms;
- financial-stability tools.
That is the essence of the banking-law dimension of hybrid warfare.
32. Regulatory Response
A Spanish response could involve several institutions simultaneously:
Banco de España
Banking supervision, operational resilience and payment-system oversight.
ECB
Where the affected institution falls under direct ECB supervision.
CNMV
Where securities markets or investment services are affected.
National Security authorities
Where the incident has broader national-security implications.
Law-enforcement authorities
Investigation and prosecution of criminal conduct.
European authorities
Coordination where EU-wide financial or cyber implications exist.
33. Importance of Financial Stability
The ultimate objective of banking regulation during a hybrid threat is not simply preventing theft.
It is preserving:
- solvency;
- liquidity;
- payment continuity;
- customer confidence;
- market functioning;
- data security;
- economic stability.
Banco de España's macroprudential framework specifically uses capital and other tools to absorb and mitigate systemic financial risks.
34. Key Legal Principles
Principle 1 — Banking infrastructure can be a national-security asset.
Principle 2 — Cybersecurity is increasingly part of prudential regulation.
Principle 3 — A cyberattack can create both private-law and regulatory consequences.
Principle 4 — Financial stability requires operational resilience.
Principle 5 — Outsourcing does not eliminate the regulated bank's responsibility.
Principle 6 — Hybrid threats can combine cyber, economic and informational instruments.
Principle 7 — National-security measures must operate within constitutional and EU legal limits.
Principle 8 — Not every cyberattack constitutes hybrid warfare.
35. Conclusion
Spanish banking law does not contain a single legal regime called "hybrid warfare banking law." Instead, the subject lies at the intersection of banking supervision, financial stability, cybersecurity, national security, criminal law, sanctions and EU financial regulation.
Spain's National Security Strategy expressly recognizes the increasing importance of hybrid strategies, while the national-security framework identifies cyber vulnerability, critical infrastructure, foreign interference and economic/financial instability as interconnected security concerns.
For the banking sector, DORA, cyber-incident reporting, TIBER-ES, prudential supervision and payment-system resilience are especially important. Banco de España currently treats cyber risks as significant threats to the continuity of payment systems and financial infrastructures.
The Spanish judicial examples also show the practical legal consequences: the Audiencia Nacional has prosecuted sophisticated cyberattacks involving manipulation of banking infrastructure, while a 2025 Spanish banking decision addressed a bank's cybersecurity responsibilities following smishing-enabled fraudulent transactions.
Thus, the central legal idea is:
Hybrid warfare → attacks on financial infrastructure → operational disruption/data compromise/loss of confidence → banking, criminal, regulatory and national-security consequences.
The modern Spanish approach therefore treats financial resilience and cyber resilience as interconnected components of the protection of the banking system.

comments