WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Ransomware Group Claims to Have Compromised Portuguese Water Utility
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Ransomware Group Claims to Have Compromised Portuguese Water Utility

Author: Alec Davison

Created: Tuesday, February 21, 2023 - 20:04

Categories: Cybersecurity

The LockBit ransomware gang claims to have successfully compromised a Portuguese municipal water utility and is threatening to leak its stolen data. At the time of writing, it is still unknown how the attackers breached the utility or what type of data was stolen.

The utility disclosed the breach on January 30, saying a cyber attack impacted some of its services but not its ability to provide drinking water or sanitation services to customers. LockBit threat actors added the municipal water utility company to the list of victims on its Tor leak site and set March 7 as the deadline to pay. The threat actors have yet to release samples of the stolen data as proof of the security breach and, as noted above, the volume and type of data stolen by the ransomware gang are unknown. The utility said in a statement: “Due to the incident, some customer services suffered constraints. In this sense, all customers who, in the last 72 hours, submitted requests for information, service requests, complaints, among others, should contact the municipal company.” Portuguese government authorities are investigating the incident.

LockBit is a ransomware-as-a-service (RaaS) group that has been active since September 2019. The group has developed several variants of ransomware products to conduct its attacks. LockBit has been the dominant ransomware strain over the past year, and according to Flashpoint the group was responsible for 30 percent of all known ransomware attacks from August 2021 to August 2022. Read more at Security Affairs.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) IOC Associated with Volt Typhoon Performed Network Enumeration on Utah Infrastructure

Jun 18, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Email Impersonation Remains a Persistent Risk for Water Utilities

Jun 18, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar