MEO Says a Mass Attack Degraded Its International Network on Monday, Six Days After ANACOM Opened the Rulemaking for the Sector's Cybersecurity Regulation
Downdetector logged a peak above 7,200 fault reports at 18:19, and problems at NOS, Vodafone and Digi too. Portugal's cybersecurity regime has been in force since April, and it gives an operator 24 hours to file an initial notification with its sector regulator.
One of Portugal's three incumbent telecoms networks spent Monday afternoon degrading in public, and by evening its operator had a name for what happened. MEO, the consumer brand of Altice Portugal, confirmed that it "was the target of a mass attack" that "caused congestion and degradation of the international network". The company said the attack produced "no intrusion into and no access to MEO or customer data", that mitigation and recovery measures were activated immediately, and that this allowed it to "control the situation quickly and restore service stability".
The public evidence of the incident was ordinary and widespread. On Downdetector, which collects user fault reports, complaints about MEO peaked above 7,200 at 18:19, covering fixed broadband, WiFi and mobile internet. The same site logged problems at NOS, Vodafone and Digi during the day, which is consistent with congestion on international routes rather than a fault inside one operator's own plant.
What makes this more than a bad afternoon is the calendar. Six days before it happened, on 8 September, the sector's regulator formally opened the rulemaking procedure for the cybersecurity regulation that will govern exactly this kind of event.
Portugal now has a cybersecurity law with deadlines in it
Until this year, the obligations on a Portuguese telecoms operator after a network security incident sat in the Lei das Comunicações Eletrónicas (Electronic Communications Law), Lei n.º 16/2022, and in ANACOM's own regulations made under it. That changed on 3 April 2026, when the Regime Jurídico da Cibersegurança (Cybersecurity Legal Regime) came into force. It was approved as an annex to Decreto-Lei n.º 125/2025 of 4 December 2025, which set its own start date at 120 days after publication, and it transposes Directive (EU) 2022/2555, the instrument generally known as NIS2.
The regime is unusually concrete about timing. Article 40 obliges essential, important and relevant public entities to notify any significant incident to the competent cybersecurity authority, and lists the parameters that decide whether an incident is significant: the number of users affected by the disruption, the total number of users of the disrupted service, how long the incident lasted, how severe the disruption to the service was, and the scale of the impact on economic and social activity. An event that knocked out broadband and mobile internet for a national operator across an afternoon clears that bar on more than one of those parameters at once.
Article 41 then requires three separate filings for each notifiable incident: an initial notification, a notification that the significant impact has ended, and a final report. There is one shortcut. If the incident is resolved within two hours of being detected, only the end-of-impact notification is required. MEO's own statement says the situation was brought under control quickly; whether "quickly" means inside two hours is now a question with legal consequences rather than a public-relations one.
Article 42 sets the first deadline. The initial notification must reach the authority without undue delay and within 24 hours of the entity concluding that a significant incident exists or may exist, unless filing it would be incompatible with mitigating or resolving the incident. It must carry a named contact, the time the incident started or was detected, a description using the taxonomy set by the Centro Nacional de Cibersegurança (National Cybersecurity Centre), and an impact estimate covering users affected, duration and geographic spread including any cross-border effect. Within 72 hours of the incident being confirmed, the entity must send an update containing an initial assessment of severity and impact.
Article 43 gives 24 hours from the end of the significant impact to notify that it has ended. Article 44 gives 30 working days from that filing for the final report, and requires weekly interim reports if the incident is still running when the deadline arrives.
ANACOM, not the CNCS, is the address
The regime splits supervision. The Centro Nacional de Cibersegurança is the national cybersecurity authority and hosts CERT.PT, the national incident response team. But Article 15 designates national sectoral cybersecurity authorities, and for electronic communications and postal services that authority is the Autoridade Nacional de Comunicações (ANACOM). A telecoms operator notifies its sector regulator.
The CNCS is not out of the picture. Article 20 requires it to pass to the Polícia Judiciária, within 24 hours, any facts of criminal relevance it learns of in the course of its work, and to pass to the Serviço de Informações de Segurança (Security Intelligence Service), within 24 hours, any facts concerning threats to internal security, cyberespionage or cybersabotage. A deliberate mass attack on the international connectivity of a national operator is not obviously outside either category.
There is also a live seam in the law. Article 9 of the decree-law revokes Articles 59 to 65 of the Electronic Communications Law, the network security and integrity provisions, but Article 10 says that revocation takes effect only once the competent bodies have replaced or revoked the regulations ANACOM adopted under the earlier framework. Until that happens, the old sectoral rules and the new national regime overlap.
The rulebook that was opened on 8 September
Closing that seam is what ANACOM started six days before the attack. On 8 September its board decided to begin the rulemaking procedure for a Regulamento Sectorial de Cibersegurança (Sectoral Cybersecurity Regulation) for the electronic communications sector, and published the decision the following day under Article 98 of the Código do Procedimento Administrativo (Administrative Procedure Code). The legal basis it cites is its own statutes, approved by Decreto-Lei n.º 39/2015, together with Articles 15 and 27 of the cybersecurity regime.
The notice does something more useful than announce an intention. It attaches a set of measures ANACOM considers to be specific needs of the electronic communications sector and which it believes should form part of the future regulation, and invites anyone with an interest to say what they think of them. Contributions must be in writing, in Portuguese, and must reach [email protected] within 30 working days of publication, which means by 22 October 2026. A draft regulation follows, and that draft goes to full public consultation, published on the ANACOM site and in the second series of the Diário da República.
The national layer beneath it already exists. On 22 June the CNCS published Regulamento n.º 756/2026, which sets the operating rules for the electronic notification platform, the conformity levels, and the minimum cybersecurity measures flowing from the Quadro Nacional de Referência para a Cibersegurança (National Cybersecurity Reference Framework). Its annexes carry the framework itself, the risk-matrix methodology, the minimum measures for essential and important entities, and the measures for relevant public entities.
What this means for customers
- Your data was not the target, on the company's account. MEO's statement is specific that there was no intrusion and no access to its own or customers' data. Congestion of an international network is a capacity attack, not a data breach, and the two carry different obligations and different consequences.
- Service credits are a contractual question, not a cybersecurity one. Nothing in the cybersecurity regime gives an individual subscriber a remedy. If your service was unusable for a material period, the route is the operator's own service-quality terms and, failing that, a complaint to ANACOM.
- A single-operator fault is a good argument for a second path. Monday's reports spanned four networks, but the depth of the failure was at MEO. Households that work from home increasingly keep a mobile plan on a different network precisely as a fallback.
- The reporting record should become public. Under the new regime the incident generates a final report, and ANACOM is the recipient. Portugal has not historically published these; whether that changes is one of the things the sectoral regulation now being drafted could settle.
- This is the second national infrastructure operator hit in six weeks. In August, a cyberattack disrupted the state water group Águas de Portugal, freezing customer channels while supply itself ran normally. The pattern in both cases is the same: the service holds, the systems around it do not.
ANACOM's consultation window runs to 22 October. It is open to anyone, and its subject is what a Portuguese telecoms operator should be required to do before, during and after precisely the kind of afternoon MEO had on Monday. The regulator could not have asked for a better-timed illustration, and the operators now have six weeks to say what they think the rules should be.