WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Ransomware Group Claims to Have Compromised Portuguese Water Utility
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Ransomware Group Claims to Have Compromised Portuguese Water Utility

Author: Alec Davison

Created: Tuesday, February 21, 2023 - 20:04

Categories: Cybersecurity

The LockBit ransomware gang claims to have successfully compromised a Portuguese municipal water utility and is threatening to leak its stolen data. At the time of writing, it is still unknown how the attackers breached the utility or what type of data was stolen.

The utility disclosed the breach on January 30, saying a cyber attack impacted some of its services but not its ability to provide drinking water or sanitation services to customers. LockBit threat actors added the municipal water utility company to the list of victims on its Tor leak site and set March 7 as the deadline to pay. The threat actors have yet to release samples of the stolen data as proof of the security breach and, as noted above, the volume and type of data stolen by the ransomware gang are unknown. The utility said in a statement: “Due to the incident, some customer services suffered constraints. In this sense, all customers who, in the last 72 hours, submitted requests for information, service requests, complaints, among others, should contact the municipal company.” Portuguese government authorities are investigating the incident.

LockBit is a ransomware-as-a-service (RaaS) group that has been active since September 2019. The group has developed several variants of ransomware products to conduct its attacks. LockBit has been the dominant ransomware strain over the past year, and according to Flashpoint the group was responsible for 30 percent of all known ransomware attacks from August 2021 to August 2022. Read more at Security Affairs.

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar