Cybersecurity incident - update

What happened

Metro Mondego was the target of a ransomware cyberattack, detected on July 6, 2026, which affected some of its internal systems. Transport service operations were not compromised. Metro Mondego immediately activated its incident response procedures, with the support of external cybersecurity experts, and notified the National Cybersecurity Center, the National Data Protection Commission, and the authorities responsible for criminal investigations, with whom it remains in contact.

What we know at this time

Available information leads Metro Mondego to consider it likely that the attackers copied information that may include personal data. The group responsible for the attack has publicly claimed responsibility, alleging possession of company information and announcing an intention to release it. It is not yet possible to confirm exactly which data were copied. As a precaution, Metro Mondego has decided to notify potentially affected individuals without waiting for such confirmation, so that they can take steps to protect themselves now.

Information for passengers

Bank card payment data were not affected: payments are processed on standalone terminals that are isolated from the affected systems. Regarding personal data, this notice applies only to holders of personalized passes; the purchase of transport tickets does not involve the recording of passengers' personal data.

Data associated with the personalized pass that may be involved include identification and contact details (such as name, date of birth, address, email, phone number, and photo), official identification numbers (CPF and the ID document number provided during registration), and transport pass usage data. These notices apply equally to passes held by minors. We advise guardians to be alert to suspicious messages, calls, or other contacts directed at the minors in their care.

Regarding the SMS sent to pass holders

On July 29, 2026, Metro Mondego sent an SMS—from the sender "MMondego"—to holders of personalized passes whose phone numbers are on file. The text sent was exactly as follows:

Metro Mondego Notice: We were the target of a cyberattack reported in the media, and personal data associated with your pass may have been copied. Please check the official Metro Mondego website for recommended precautions. We never request data, codes, or payments via SMS, phone call, or email.

The Metro Mondego SMS contains no links and requests no information. If you receive a message different from this one—containing links, attachments, or requests for data, codes, or payments—do not reply or open the links, as it is not a communication from Metro Mondego. Please report such messages to incidente@metromondego.pt or call 239 488 109.

Pass holders whose phone numbers are not in our records, or whose records are outdated, will not receive this SMS but are covered by the information on this page.

Individuals who contacted Metro Mondego via email

The names, email addresses, and phone numbers of individuals who exchanged messages with Metro Mondego addresses—whether institutional or belonging to employees—may also be affected. For these individuals, the primary risk is receiving fraudulent messages impersonating Metro Mondego or their usual contacts.

Employees, suppliers, and other entities

Employees (current and former), suppliers, and other individuals and entities with contractual relationships with Metro Mondego will receive specific individual communications tailored to the data relevant to each group. This notice serves as the public announcement for any individuals who cannot be contacted individually right away.

Precautions to take

• Be wary of messages, emails, or calls claiming to be from Metro Mondego, banks, or utility companies that request personal data, codes, or payments—even if they correctly cite your details. That is precisely what makes them dangerous.

• Do not open links or attachments in unexpected messages.

• Treat any request to change banking details or urgent payment requests as suspicious; always verify using official contact channels you already know, rather than those provided in the message you received.

• Be alert for contracts, invoices, records, or correspondence in your name that you do not recognize.

• Metro Mondego never requests passwords, authentication codes, or banking details via telephone, SMS, or email.

Any suspicious communication should be reported to the email address incidente@metromondego.pt or by calling 239 488 109. For questions regarding personal data, you may contact the Data Protection Officer at dpo@metromondego.pt.

Metro Mondego will continue to publicly update this information as the investigation progresses and will notify individuals whose data is confirmed to be affected: individually, whenever contact details are available, and via public announcement in all other cases. We regret any concern this situation may cause and reaffirm our commitment to transparency and the protection of the data entrusted to us.

News Image