Last updated 1 month ago
In April 2026, data allegedly obtained from CTT, Portugal's national postal service, was posted to a public hacking forum. The breach exposed 468,124 unique email addresses along with names, phone numbers, and parcel tracking numbers.
The attack vector is unauthorized access, as the data was posted to a public forum. The exfiltrated data includes email addresses, names, phone numbers, and parcel tracking numbers, which can be used to retrieve the tracking history of parcels.
No further details on post-incident developments are available in the article.
Data posted to a public hacking forum
CTT, a national postal service handling sensitive customer data, suffered a breach exposing 468k records including email addresses, names, phone numbers, and parcel tracking numbers. This incident highlights the need for robust access controls and monitoring to prevent unauthorized data exfiltration, as well as the importance of securing tracking numbers that can reveal parcel history.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector