Hackers Selling 120 Gigabytes Linked to Portugal's Spy Agencies Got In Through a Web Contractor's Test Server, the SIRP Says
The intelligence system says nothing classified was taken and its own systems were never breached, but parts of a limited number of job applications sat on the contractor's server, alongside data from dozens of other clients.
Data that hackers say they took from Portugal's intelligence services came from a web contractor's test server, not from the services themselves, the Sistema de Informações da República Portuguesa (Intelligence System of the Portuguese Republic, SIRP) said on Thursday. What leaked, according to the SIRP, includes parts of a limited number of job applications sent to the services.
The statement followed an advertisement posted on Wednesday on a cybercrime forum offering 120 gigabytes of data described as coming from the SIRP. According to the Portuguese technology site Pplware, cited by Lusa, the sellers claim 312,144 files: 96 databases, the source code of 180 websites, private documents, emails, personal data and information about systems and applications.
What the SIRP says happened
In a written answer to Lusa, an official source at the SIRP said the data "will have been obtained through a cyberattack on the development server (used for testing)" of the company hired in 2025 to design the public websites of the SIRP and its two services, the Serviço de Informações de Segurança (Security Intelligence Service, SIS) and the Serviço de Informações Estratégicas de Defesa (Strategic Defence Intelligence Service, SIED). Those three portals, the source said, "do not contain classified information".
For the SIRP itself, the material corresponds to "some elements of a limited set of applications" submitted to it, which the contractor "will have transferred to an instance under its responsibility". The SIRP recruits through its own website, which carries a careers section and an online application form. It did not say how many applicants are affected or what the "elements" are.
The haul may also hold "information from the websites of dozens of entities, public and private, that hired the same service provider" to build their sites, the SIRP said. Neither the SIRP nor Lusa named the company.
What the SIRP says did not happen
The services were firm on three points. "There was no intrusion into the infrastructure and computer systems of the SIRP or the data centres of the SIS and the SIED," the source wrote, adding that the servers behind the public websites "are totally segregated" from those used in the services' work. "There is no evidence or indication of any compromise of classified or operational information. As such, any reference to possible access to classified information is unfounded." And although the forum post names the sirp.pt domain as its target, the SIRP said its public website "was not the target of a cyberattack".
The contractor reported the incident to the SIRP itself. The SIRP says it took every step to contain it, reported the facts to the Procuradoria-Geral da República (Prosecutor General's Office) and "will continue to assess the situation".
Why it still matters
Even on the SIRP's account, the episode exposes the part of an intelligence service that is hardest to keep quiet: the people who want to work for it. Their parliamentary watchdog, the Conselho de Fiscalização do SIRP (SIRP Oversight Council), lists espionage and cyberthreats among the threats the services watch, and its latest opinion, delivered in September, gave its longest passage to staffing.
The SIRP's account also suggests real applicant data was copied to a test server. Under the EU's General Data Protection Regulation, an organisation that suffers a personal data breach must report it to the data protection authority, in Portugal the Comissão Nacional de Proteção de Dados (National Data Protection Commission), within 72 hours, and must tell the people affected directly when the breach is likely to put their rights at high risk. The SIRP did not say whether applicants have been told.