TheGentlemen ransomware hits Portugal's Metro Mondego (Coimbra light-rail); operator confirms attack, notifies CNCS and CNPD
Metro Mondego confirms a 6 July ransomware attack on internal systems, transport operation unaffected; TheGentlemen claims data theft
Analysis
Metro Mondego (the public operator of the Metrobus light-rail line between Lousã and Coimbra, Portugal) announced on 2026-07-17 that it was hit by a ransomware attack on 6 July that affected "part of its internal systems" without compromising the transport service ("um ataque informático a 6 de Julho que afectou 'parte dos seus sistemas internos', mas sem comprometer a operação do serviço de transporte") (Campeão das Províncias, 2026-07-17). The operator confirms it activated incident-response procedures with external cybersecurity experts and notified the competent authorities, Portugal's National Cybersecurity Centre (CNCS), the National Data Protection Commission (CNPD) and criminal-investigation authorities, and that its investigation is examining whether the attackers copied data from the affected internal systems; it cannot yet determine whether any personal data of passengers, employees or suppliers is involved, but states passenger payment data was not affected (Campeão das Províncias, 2026-07-17). The attack was claimed by the ransomware-and-extortion group TheGentlemen (Microsoft: Storm-2697; registry-tracked), which posted that it extracted confidential documentation and threatened to publish absent payment (TugaTech, 2026-07-16).
Cited evidence
A Metro Mondego anunciou esta sexta-feira que foi alvo de um ataque informático a 6 de Julho que afectou “parte dos seus sistemas internos”, mas sem comprometer a operação do serviço de transporte.
A ação foi reivindicada pelo grupo de cibercriminosos Thegentlemen, que afirma ter conseguido extrair documentação confidencial
Sources2
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.