On February 18, 2023, Portuguese municipal water utility Aguas do Porto appeared on the LockBit 3.0 ransomware leak site, claiming that internal files had been exfiltrated during a ransomware attack. Anyone whose personal information appears in municipal utility records — from billing addresses and payment details to service contracts — may now be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch aguasdoporto.pt
Get alerted the next time aguasdoporto.pt files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about aguasdoporto.pt’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The LockBit 3.0 leak site listing states that Aguas do Porto suffered a ransomware incident in which attackers successfully exfiltrated internal files. The disclosure does not quantify how many records were taken, list specific data types beyond “internal files,” or reveal the ransom demand. It simply marks the Portuguese water-management company as “published,” a standard signal that negotiations failed and the group has begun releasing or intends to release the stolen data. Public copies of the leak site via ransomware.live preserve this exact entry with the timestamp February 18, 2023.
Why This Matters for You and Your Family
Aguas do Porto manages the entire water cycle for the city of Porto, handling customer names, addresses, phone numbers, contract details, bank-account references for direct debits, and consumption records. When such operational files leave the company’s control, the information can be used to build convincing phishing campaigns, impersonate utility staff, or link your home address to other online identities. Because utilities rarely notify individual customers quickly, many families remain unaware that their data is circulating on dark-web forums months or years later.
February 18, 2023 marks the moment the data became publicly leveraged as extortion material. Even if the full archive has not yet been downloaded by hundreds of threat actors, its mere presence on a well-known ransomware portal increases the likelihood that your details will surface in future sales threads or be bundled into larger datasets.