Menu
Browse
Date

Nov 2022

Location

Portugal

Status

Historical

Timeline
Occurred
Nov 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

A cyberattack targeted the Instituto Nacional de Emergência Médica (INEM), compromising credentials of approximately 2,492 professionals and disrupting non-critical systems such as scheduling platforms and password management tools. The attack did not impact emergency medical services or critical operational infrastructure, and no evidence confirmed data compromise. Security protocols were activated, with immediate notifications made to national cybersecurity authorities and law enforcement. While credential theft was indicated in deep web forums, the organization maintained that core functions remained unaffected throughout the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around November 30, 2022, the Instituto Nacional de Emergência Médica (INEM) experienced a cyberattack targeting its information systems. The intrusion, detected in early December, compromised platforms managing schedules, internet-based work tools, and password change functionalities. Initial evidence suggested attackers exfiltrated credentials belonging to 2,492 INEM professionals, with data leaks appearing on deep web cybercrime forums by December 10. INEM activated predefined security protocols and implemented necessary response measures, emphasizing that critical emergency medical systems remained unaffected and no evidence confirmed data compromise. The organization formally notified Portugal’s National Cybersecurity Center (CNCS) and Judicial Police but provided limited details in subsequent communications, declining to address specific questions from media inquiries.

Cyber Incident Image

Separately, the Porto campus of Universidade Católica Portuguesa suffered a cyberattack in late November 2022, disrupting academic services for two weeks. The criminal intrusion forced suspension of electronic tools for students, faculty, and researchers, though email systems remained operational. Users resorted to external file-transfer platforms like Dropbox and WeTransfer during the outage. The university, as a private entity not classified as critical infrastructure, notified the National Data Protection Commission (CNPD) instead of CNCS. Service restoration occurred gradually, requiring password resets conducted off-campus due to disabled Wi-Fi access. Internal communications confirmed the criminal origin of the attack but stated no evidence of personal data compromise. Both institutions maintained public assurances regarding data integrity while acknowledging operational disruptions.

Sources
Sources available to members
1 source