Back

A 120 GB Data Leak Claim Puts Portugal’s Intelligence Umbrella in the Spotlight

A hacker says they’re holding 120 GB of data taken from SIRP, the body that oversees Portugal’s intelligence services. It’s a claim, not a confirmed fact, and that distinction matters. But if even part of it holds up, this cyberattack Portugal story is a serious one.

What the hacker says they have

SIRP, the Portuguese Republic’s Intelligence System, coordinates two agencies: the SIS, which handles internal security, and the SIED, which focuses on strategic intelligence and external security. That’s a tough place to find a crack.

In a post dated October 6, 2026, a hacker says they’re selling data tied to sirp.pt.

The listing mentions:

  • 120 GB spread across 312,144 files
  • the contents of 96 databases
  • source code from 180 websites
  • internal documents, emails, personal data and details about systems and applications

Big numbers sound scary. Still, none of this has been publicly confirmed by SIRP so far, and no official statement has appeared.

The sample: ordinary people, not spies

FrenchBreaches looked at a sample of 1,000 entries said to come from the leak. Interestingly, they look like job applications rather than classified material. The records include names, ID card numbers, Portuguese tax numbers (NIF), phone numbers, birth dates, gender, email and postal addresses, and nationalities.

There’s more: studies, work history, driver’s licenses, languages, skills, motivations and the positions people applied for. References to CVs and other attachments show up as well.

Think of it as a filing cabinet from a recruitment office. Not the vault, but still full of details nobody wants floating around. If you ever applied to work with an organization like this, that’s a sobering thought, because identity data like that is exactly what fraudsters love.

oWrgbt3.png

Why this one feels different

Most breaches hit retailers, airlines or telecoms. This one points at the organization sitting above Portugal’s civilian intelligence. Even if the exposed material turns out to be mostly applicant data, the name attached to it raises the stakes.

What we don’t know yet

Plenty is still missing. Nobody has shown how the intrusion happened, which systems were touched, or whether the 120 GB figure is real. Those answers will have to come from a proper data breach investigation, and until SIRP or the authorities speak, the hacker’s version is that.

So what should you do with this news? Treat it with care. Don’t assume the worst, and don’t wave it off either. If you’ve applied for a role with a Portuguese public body, keep an eye on unexpected emails or calls asking for personal details, and be wary of anything that mentions your CV or application.

Keeping an eye on how it develops

Stories like this tend to change fast. A denial, a confirmation or a fuller sample can reshape the picture within days. devs.com.pt highlights that cybersecurity has become a daily concern for the whole tech sector, not security specialists. And if you want to compare notes with people who deal with these risks for a living, a few technology events are a good place to start.

For now, the honest summary is short. A hacker has made a big claim, a small sample suggests applicant data is involved, and the rest is waiting for facts.