CSIDB logo
Incident

Universidade do Algarve

Incident posture

Attack window
Nov 2024
Location
Portugal
Status
Unknown
CIA posture
Available to members
Updated
2025-12-26 00:00

Linked entities

Victim
Universidade do Algarve
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Nov 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted the University of Algarve's academic management system, resulting in unauthorized access and exfiltration of personal data from applicants, students, and staff, including names, email addresses, phone numbers, and bank account details. Despite the breach, regular academic and research activities continued without disruption. The institution promptly notified affected individuals about compromised information and protective measures while reporting the incident to relevant national cybersecurity and data protection authorities. The university expressed regret over the incident and reaffirmed its commitment to enhancing information security protocols.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The University of Algarve (UAlg) experienced a cyberattack targeting its academic management system between November 14 and 19, 2024. Hackers infiltrated the system during this period, exfiltrating personal data belonging to applicants, students, and staff members. The compromised information included names, email addresses, telephone contacts, and, in some cases, IBAN bank account numbers. The university confirmed the breach after detecting unauthorized access but maintained regular academic and research activities throughout the incident without interruption. On November 19, UAlg terminated the attack by deploying a software update to secure the compromised system. The institution immediately notified affected individuals through direct communication, specifying which personal data had been stolen and advising on protective measures to mitigate potential misuse.

UAlg reported the incident to Portuguese authorities upon discovery, including the National Cybersecurity Centre (CNCS), the Data Protection Commission (CNPD), and the Judicial Police’s Cybercrime and Technological Crime Unit (UNC3T). Investigations by these entities are ongoing to determine the attack’s origin and full scope. In public statements, the university expressed regret for the incident and its potential consequences, emphasizing its historical commitment to information security. UAlg acknowledged the need to reinforce its cybersecurity protocols and affirmed its intent to maintain and improve safeguards for its academic community’s data. No operational disruptions to university functions occurred beyond the data breach, and no ransomware or financial demands were mentioned in available reports.

Sources

Sources available to members: 2 sources.

CSIDB