CSIDB logo
Incident

Águas e Energia do Porto

Incident posture

Attack window
Jan 2023
Location
Portugal
Status
Historical
CIA posture
Available to members
Updated
2026-03-08 23:59

Linked entities

Victim
Águas e Energia do Porto
Threat actors
1 actor
Sources
3 sources

Timeline

Occurred
Jan 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The LockBit ransomware gang compromised a Portuguese municipal utility responsible for water supply, wastewater management, public lighting, and photovoltaic operations, threatening to leak stolen data unless demands were met. While the attack disrupted customer service channels—requiring users to resubmit recent requests—it did not impact core water or sanitation services. Investigations by national cybersecurity and judicial authorities are ongoing, with LockBit having previously targeted the Port of Lisbon and a third-party IT provider linked to the utility, where customer passwords were allegedly exfiltrated.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 30, 2023, Aguas do Porto, a Portuguese municipal utility responsible for water supply, wastewater management, public lighting, and photovoltaic parks, disclosed a cyber attack that disrupted some customer-facing services. The incident did not impact core water supply or sanitation operations. Customers who submitted information requests, service tickets, or complaints in the preceding 72 hours were instructed to re-contact the company due to system constraints caused by the breach. The LockBit ransomware gang later claimed responsibility, listing Aguas do Porto on its Tor-based leak site with a threat to publish stolen data by March 7, 2023. No samples of the allegedly exfiltrated data were initially released, leaving the exact scope and nature of compromised information unverified.

Portugal’s National Cybersecurity Center and Judiciary Police launched an investigation into the incident. The attack followed a December 2022 LockBit intrusion against the Port of Lisbon, which similarly did not disrupt critical operational systems. LockBit also breached Divultec, an IT services provider, stealing sensitive customer data that reportedly included Aguas do Porto passwords. The utility did not publicly confirm whether the Divultec breach facilitated the January intrusion or elaborated on technical containment measures. Service restoration timelines and forensic findings remained undisclosed in available reporting.

Sources

Sources available to members: 3 sources.

CSIDB