Telemadrid suffered a massive ransomware attack that hit its production systems and even disrupted its broadcast signal. The Spanish public broadcaster recovered its critical systems without paying a ransom, relying on its backup infrastructure and joint work with SoftwareOne. The case offers a lesson that goes well beyond this one TV network: having backups doesn’t guarantee you can recover from ransomware if the attacker manages to encrypt the copies too.
The Telemadrid ransomware attack in 20 seconds
- The ransomware disrupted broadcasting and encrypted Telemadrid’s production systems.
- Backups stored on Dell Data Domain survived the attack.
- Recovery could initially be carried out locally, even with communications affected.
- Telemadrid didn’t pay a ransom and recovered its critical systems.
- The architecture also included an off-site copy via Azure Cloud Tier.
Recovering from a cyberattack like this is especially difficult at a television network. It isn’t enough to restore documents or administrative applications. There are production and broadcast systems that run 24 hours a day, and any downtime directly affects the service.
According to the case study published by SoftwareOne, the attackers encrypted production systems and disrupted broadcasting. Potential damages were valued in the millions of euros. The network also had to recover access to its infrastructure while part of its communications remained compromised.
The key difference was that the ransomware failed to also disable the copies used for recovery.
When ransomware also goes after the backup
Modern ransomware attacks don’t always stop at finding servers and computers to encrypt.
Attackers know that an organization with recoverable backups has far less incentive to pay. That’s why the backup infrastructure itself is a particularly valuable target during an attack.
Deleting copies, encrypting them, or obtaining administrative credentials for the protection platform can leave the victim without a fast way to recover its systems.
Telemadrid was running Dell PowerProtect Data Domain DD6400 systems together with Data Protection Suite. The local copies stored on this infrastructure weren’t compromised by the ransomware, according to the information published by SoftwareOne.
That let the recovery process run from local storage.
The difference matters.
If an organization has to recover several terabytes from an external cloud while its communications are impaired, bandwidth can become a new bottleneck. A remote copy protects against certain disasters, but it isn’t always the fastest way to restore large volumes of data — a trade-off that shows up in how enterprises still lean on systems like Dell’s Data Domain and DD Boost as a fast, local backup target.
In this case, the team was able to transfer data directly from Data Domain to the rebuilt infrastructure.
The affected servers weren’t simply restored and reconnected to production, either.
SoftwareOne says systems were installed from scratch inside an isolated environment, and the recovered virtual machines were verified before being brought back into Telemadrid’s infrastructure.
The network regained full console access after 48 hours and then gradually restored its various production services.
According to the published case study, 100% of the data considered critical was recovered, and no money was paid to the extortionists.
A second layer outside the data center
The architecture also included Azure Cloud Tier.
The approach involved moving historical data and older copies to Microsoft Azure, creating a second layer of protection outside the main data center.
That separation serves a different purpose than the local copy.
The local infrastructure delivers recovery speed. A geographically separate copy protects against scenarios where the problem hits the data center itself: fires, floods, serious physical damage, or the complete loss of the facility.
Combining different locations and technologies follows the same logic as the 3-2-1 backup rule: keep three copies of your data, store them on at least two different types of media or systems, and keep one of them off-site.
In recent years, this approach has been reinforced with concepts like immutability and isolation.
An immutable copy prevents data from being modified or deleted for a set period, even if an attacker manages to gain a certain level of access to the environment.
Isolation, or an air gap, tries to keep the production infrastructure and all of its copies from sitting within the same attack domain.
Not every solution labeled air-gapped is physically disconnected. There are logical architectures designed to provide similar levels of separation. What matters is that compromising the production system doesn’t automatically hand over the ability to destroy every path back to recovery.
For David Carrero Fernández-Baillo, co-founder of Stackscale (Grupo Aire) and a cloud infrastructure expert, that separation is precisely one of the main lessons from the incident:
“The detail that makes the difference here isn’t just having a backup, it’s that the copies withstood the attack itself. The classic ransomware mistake is that the encryption reaches the backups too; that’s why immutability (WORM) and an isolated layer are what let you recover without paying a ransom.”
Carrero also highlights two indicators that can look similar but actually measure different problems: RPO and RTO.
The recovery point objective (RPO) determines how much data an organization can afford to lose. The recovery time objective (RTO) sets how long it can take to get back up and running.
At a TV network broadcasting around the clock, the second one can be especially demanding — a challenge that looks a lot like what DRaaS setups are designed to solve when a recovery plan has to actually work under pressure, not just on paper.
“With a 24/7 broadcast on the line, what’s critical isn’t just the RPO but the RTO: every minute without a restore is a minute of dead air,” Carrero says.
A backup that’s never restored can give you a false sense of security
The Telemadrid case is also a reminder of a basic distinction between making backups and having a recovery system.
An organization can run backups daily for years and discover during an incident that they’re corrupted, incomplete, encrypted, missing the credentials needed to use them, or that the time required to restore them is incompatible with keeping the business running.
That’s why periodic restore testing is part of the process.
“Two things usually decide a case like this: testing restores on a regular basis, because an unverified backup isn’t really a backup, and applying the 3-2-1 rule so that no copy shares the same failure domain,” explains the Stackscale co-founder.
Preparation also means knowing what needs to be recovered first.
Not every server carries the same importance. Identifying critical applications, dependencies, databases, identity services, and a restoration order can significantly cut the time needed to get back to operating.
Ransomware has turned backup into part of the cybersecurity strategy rather than just a systems-administration task — a shift that also shows up in how ransomware is gaining ground even as other threat categories decline in critical environments.
A policy designed to handle the accidental deletion of a file can fall short against an attacker who has spent days inside the network, obtains administrative privileges, and deliberately sets out to destroy the copies before launching the encryption.
Telemadrid also had a managed backup service with continuous monitoring in place. During the crisis, the SoftwareOne team joined the protocol led by the network and worked continuously until the environment was stabilized.
The outcome offers a lesson that applies to much smaller organizations too.
The question shouldn’t just be “is there a backup?” You also need to know who can delete it, whether it can be modified, where it’s stored, how long it takes to restore, and what happens if the ransomware compromises the servers and the communications at the same time.
Telemadrid managed to answer those questions before it ever had to decide whether to pay the attackers.
As Carrero sums it up, “cybersecurity is won in the preparation, not the reaction.”
Frequently Asked Questions
Did Telemadrid pay the ransomware ransom?
No. According to the case study published by SoftwareOne, the network recovered its critical systems without making any payment to the extortionists.
How did Telemadrid manage to recover its data?
Local copies stored on Dell PowerProtect Data Domain systems weren’t compromised and allowed for local recovery. The architecture also included Azure Cloud Tier as a second, off-site layer of protection.
What’s the difference between RPO and RTO?
RPO sets the maximum amount of data that can be lost since the last recoverable backup. RTO measures how long a service can stay down before it needs to be restored.
Why does immutability matter against ransomware?
Because it’s designed to stop a copy from being modified or deleted for a set period. That makes it harder for an attacker who compromises the production infrastructure to also destroy every point the organization could recover from.

