CSIDB logo
Incident

Portugal Telecom

Incident posture

Attack window
May 2017
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2026-09-03 13:47

Linked entities

Victim
Portugal Telecom
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major telecommunications firm based in Portugal was among the global victims of the WannaCry ransomware attack, which exploited the EternalBlue vulnerability in unpatched Microsoft Windows systems to spread rapidly across networks. The ransomware encrypted data and demanded ransom payments in Bitcoin, affecting numerous organizations worldwide across sectors including energy, telecommunications, and government. As a victim, Portugal Telecom experienced operational disruption linked to the widespread propagation of the malware, alongside other companies such as Telefonica, MEGAFON, Iberdrola, Petrobras, and entities like the UK NHS and the Brazilian Foreign Ministry. Responses to the incident involved emergency measures such as system shutdowns and forensic investigations to contain the damage and address data integrity risks.

Motives

Detailed motive labels are available to members.

5 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 12, 2017, a large number of organizations around the world were hit by the WannaCry ransomware attack, a fast-spreading campaign that exploited a vulnerability in unpatched Microsoft Windows systems. The vulnerability, known as EternalBlue, had been stolen from the U.S. National Security Agency and was used by the attackers to propagate the ransomware across connected networks. Once a machine was compromised, WannaCry encrypted files on the system and displayed a ransom note demanding payment in Bitcoin in exchange for the decryption key. The attack was notable for the speed at which it spread, leveraging the underlying Windows flaw to move rapidly from one vulnerable host to another within affected organizations and across the internet.

The incident had a particularly heavy impact on telecommunications companies, energy providers, and government entities. Among the organizations publicly identified as affected were the UK National Health Service, Brazilian Ministry of Foreign Affairs, Spanish telecommunications company Telefonica, Russian telecommunications firm MEGAFON, and energy companies Iberdrola and Petrobras. In each case, the ransomware interfered with normal business operations, forcing the affected organizations to take urgent steps to contain the spread of the malware and restore affected systems. The breadth of the victim list reflected the global reach of the campaign and the widespread presence of unpatched Windows systems within both private and public sector networks.

Organizations responded to the attack with a combination of immediate containment measures and longer-term remediation efforts. Many of the affected entities chose to shut down portions of their networks in order to prevent further propagation of the ransomware, accepting short-term disruption as a necessary cost to limit the overall damage. Forensic teams were engaged to investigate the scope of the infections, identify the entry points used by the attackers, and confirm whether data had been exfiltrated or solely encrypted. Patching of vulnerable Windows systems was a central part of the response, as was the restoration of data from backups where possible, in order to avoid paying the ransom demanded by the attackers.

The legal and regulatory consequences of the incident were significant for the affected organizations. Concerns around data integrity were prominent, as the encryption of files by the ransomware raised questions about the reliability and availability of critical business records. Affected organizations faced regulatory scrutiny from data protection authorities and other oversight bodies, particularly where the disruption affected the delivery of essential services, as was the case with the UK NHS. In addition, the possibility of lawsuits from customers, patients, or business partners whose data or services were affected added another layer of legal exposure for the impacted companies.

The WannaCry attack underscored how a single unpatched vulnerability could be leveraged to cause widespread disruption across multiple industries and geographies. By exploiting EternalBlue, the attackers were able to automate the propagation of the ransomware to a scale rarely seen in previous malware campaigns. The rapid spread of the infection highlighted the importance of timely patch management and network segmentation as defensive measures, even though the specific responses taken during the event focused on containment, forensics, and restoration. The incident remains a referenced example of the risks associated with delayed patching and the potential global consequences of vulnerabilities in widely used software.

Sources

Sources available to members: 1 source.

CSIDB