A Ransomware Attack on Coimbra's Metro Mondego May Have Copied Pass-Holders' ID, Address and Tax Data
Metro Mondego, the operator of Coimbra's electric metrobus, says a 6 July ransomware attack may have copied the data of personalised-pass holders — names, addresses, phone numbers, photos, NIF and ID numbers. Ticket-buyers and bank-card data were unaffected. The breach has been reported to the CNCS,
The company that runs public transport between the Lousã hills and Coimbra has told its passengers that a cyberattack earlier this month may have copied their personal data. Metro Mondego, operator of the electric metrobus service linking Lousã and the university city of Coimbra, said the intrusion — a ransomware attack detected on 6 July 2026 — reached internal systems that hold the records of holders of a personalised travel pass.
The attackers, the company said, publicly claimed responsibility and asserted that they were in possession of information taken from the firm. That is the hallmark of a modern ransomware operation, which increasingly steals data before encrypting it so that victims can be pressured to pay twice — once to recover their systems and again to stop the stolen files being leaked.
What may have been taken
The data at risk belongs to holders of a passe personalizado (personalised transport pass), the named cards that regular commuters register in order to travel. According to Metro Mondego, the fields that may have been copied include names, dates of birth, addresses, telephone numbers and photographs, together with official identifiers — the Número de Identificação Fiscal (tax number, or NIF) and identity-document numbers — as well as records of how and when the pass was used. Also potentially exposed were the names, e-mail addresses and phone numbers of people who had corresponded with company contacts.
Passengers who simply buy single or top-up tickets are not affected, the operator stressed, because an ordinary ticket purchase does not involve registering any personal data. Bank-card details used for payments were held in isolated systems that the attackers did not reach, the company added, and the transport service itself continued to run normally throughout.
Who has been notified
Metro Mondego said it had reported the breach to the Centro Nacional de Cibersegurança (National Cybersecurity Centre, or CNCS), the Comissão Nacional de Proteção de Dados (National Data Protection Commission, or CNPD) and the criminal-investigation authorities. Under the EU’s General Data Protection Regulation, an operator that suffers a breach likely to put individuals at risk must inform the data-protection regulator, and in serious cases the affected people themselves — which is effectively what this public notice does.
The Sistema de Mobilidade do Mondego (Mondego Mobility System) is the long-delayed transit project that finally replaced the old Lousã rail line with a fleet of electric bus-rapid-transit vehicles running on a dedicated corridor into Coimbra. Having spent two decades as a byword for stalled infrastructure, the service is now dealing with a very contemporary problem instead.
What pass-holders should do
For anyone who holds a Metro Mondego personalised pass, the practical risk is not fraud on a bank card — those systems were untouched — but targeted phishing. A criminal armed with a real name, address, phone number and NIF can craft convincing messages that appear to come from a bank, the tax authority or the transport operator itself. Residents in the Coimbra region are well advised to treat unexpected calls, texts or e-mails referencing their pass with suspicion, to avoid clicking links in such messages, and never to hand over passwords or card details in response to an unsolicited approach. Ransomware crews rarely use the data themselves; they sell it on, and the phishing that follows a breach can arrive months later.