🇵🇹 Daily Portugal news for expats & investors — FREE Subscribe

A Sophisticated Cyberattack Disrupts the State Water Group Águas de Portugal, Freezing Customer Channels While Supply Runs Normally

Portugal's largest water utility was hit by a 'highly complex' cyberattack that froze its back-office systems and customer channels — but supply, water quality and, so far, personal data were untouched.

A Sophisticated Cyberattack Disrupts the State Water Group Águas de Portugal, Freezing Customer Channels While Supply Runs Normally

Portugal's largest water utility has spent this week rebuilding parts of its digital backbone after what it describes as a "highly complex" cyberattack. The Grupo Águas de Portugal (Waters of Portugal Group), the state-owned holding that sits at the centre of the country's public water supply and sanitation, confirmed on Tuesday, 4 August, that the intrusion — detected the previous Friday — knocked out part of its information systems and its customer-facing channels. Crucially, it stressed that taps kept running: water supply and quality were never in danger.

The group, known by its initials AdP, is not a single company but a federation of 13 operational companies that between them run bulk water abstraction, treatment and wastewater services for a large share of Portuguese municipalities. An attack that reaches across that structure is exactly the kind of incident the country's cybersecurity authorities have been warning about, and AdP's response — pulling systems offline and calling in three separate national bodies — reflects the seriousness with which critical-infrastructure operators are now expected to treat such events.

What actually happened

In its public statement, AdP said it had been "targeted by a highly complex cyberattack affecting part of the information systems," which temporarily constrained administrative processes and the channels customers and partners use to reach the company. The disruption was concentrated on back-office IT and contact platforms rather than the operational technology that physically moves and treats water.

The company was emphatic on the point that matters most to households: "Water supply and sanitation services continue functioning normally across all group companies." In other words, the systems that control pumps, reservoirs and treatment plants were not compromised, and there is no risk to the quality of what comes out of the tap. As of the announcement, AdP said recovery was under way, with systems being restored gradually.

Was personal data exposed?

For customers, the second question after supply is data. Here AdP was careful but reassuring: it said it had found no evidence of unauthorised access to personal information or of data being exfiltrated from its systems. That is a preliminary finding rather than a final verdict — forensic work on incidents of this kind can take weeks — but it is the assessment the company was willing to stand behind at the time of disclosure.

Notably, AdP has not publicly classified the attack. It has not said whether it was ransomware, a data-theft operation, or something else, describing it only as "high complexity." That reticence is common in the early days of an investigation, when saying too much can compromise both the forensic trail and any law-enforcement action.

Who was called in

AdP reported the incident to three national authorities, a combination that maps neatly onto Portugal's incident-response architecture:

  • Polícia Judiciária (Judicial Police), whose cybercrime units handle the criminal investigation;
  • Centro Nacional de Cibersegurança (National Cybersecurity Centre, or CNCS), the technical authority that coordinates responses to incidents affecting essential services; and
  • Comissão Nacional de Proteção de Dados (National Data Protection Commission, or CNPD), the regulator that must be notified when personal data may be at risk.

The involvement of the CNPD is a formality that flows from the EU's data-protection rules: when there is any prospect that personal data has been breached, organisations are expected to notify the regulator promptly, even before they know the full extent of the damage. Bringing in the CNCS, meanwhile, reflects AdP's status as an operator of an essential service under Portugal's cybersecurity framework, which now sits within the EU's tightened NIS2 regime for critical sectors such as water, energy and health.

Part of a rising trend

The AdP breach lands against a backdrop of steadily climbing attacks on Portuguese organisations. The CNCS logged 3,864 cybersecurity incidents in the country in 2025, up roughly 40% on the previous year, and public bodies and infrastructure operators have featured prominently among the targets. Water utilities are a particularly sensitive category: they are essential, geographically dispersed, and increasingly run on networked digital systems, which widens the surface an attacker can probe.

For residents, the practical takeaway is narrow but worth noting. There is no reason to change how you use your water, and no need to act on any unexpected message purporting to come from your water company while its channels are disrupted — a period like this is precisely when opportunistic phishing tends to spike. If you need to contact your local AdP company and its usual channels are down, wait for official confirmation that services have been restored rather than following links sent by email or text.

AdP has promised to keep customers informed as it completes the clean-up and the investigation proceeds. The reassuring headline is that the water itself was never the target's to take; the harder question — who was behind the intrusion, and what, if anything, they reached — will be answered over the weeks ahead.