CSIDB logo
Incident

Câmara Municipal de Loures

Incident posture

Attack window
Sep 2022
Location
Portugal
Status
Historical
CIA posture
Available to members
Updated
2025-10-16 00:00

Linked entities

Victim
Câmara Municipal de Loures
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The municipality of Loures experienced a malicious and deliberate cyberattack aimed at disrupting its IT systems and services. Security systems detected the incident, prompting immediate containment and mitigation efforts by local authorities, who reported the attack to national law enforcement and cybersecurity agencies. While restoration of affected services was anticipated to occur shortly, the municipality did not disclose specific impacted systems or confirm whether citizen or internal data was compromised during the breach.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 22, 2022, the Municipal Council of Loures, a municipality in the Lisbon district of Portugal, experienced a targeted cyberattack characterized by local authorities as "malicious and deliberate." The attack specifically aimed to disrupt the municipality's information systems and services, though the exact technical nature of the intrusion was not publicly disclosed. The council's internal security systems detected the attack, triggering an immediate operational response to contain and mitigate the incident's effects. Municipal leadership, under Mayor Ricardo Leão of the Socialist Party (PS), formally reported the incident to Portugal's Judicial Police (Polícia Judiciária) and the National Cybersecurity Center (Centro Nacional de Segurança), initiating law enforcement and national security coordination. No initial details were provided regarding the specific municipal services impacted, the duration of system compromise, or whether citizen or municipal data was accessed or exfiltrated during the breach.

The municipality prioritized containment measures to prevent further system degradation while working to restore normal operations. Officials publicly stated that service restoration was expected to occur "very soon," though no definitive timeline or technical recovery milestones were shared. The incident response did not involve public disclosures about attacker identity, motives, or demanded ransoms, nor did authorities confirm whether the attack involved ransomware, data theft, or purely disruptive objectives. Operational continuity efforts focused on IT system remediation, with no reported interruptions to essential civic services beyond the unspecified IT disruptions. The lack of detailed public statements about compromised infrastructure or data exposure risks left the full operational and reputational impacts unquantified in the immediate aftermath.

Sources

Sources available to members: 1 source.

CSIDB