Summary
- Environment: Locky smart-locker network
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
Contact data associated with Locky delivery notifications and a separately quantified verified HIBP email corpus. [1][2]
Documented data types include:
- Contact information — CTT described delivery-notification contact data; HIBP lists email addresses and phone numbers for the verified corpus. [1][2]
- Names — Names listed in the HIBP DataClasses for the verified corpus. [1][2]
A cited record reports 468,124 records (Unique email addresses represented in the verified HIBP corpus; not a CTT-confirmed number of customers, parcels, accounts, or affected people; as of 2026-05-19). [1][2]
CTT said the exposed data did not include full addresses, passwords, or financial data. [2]
CTT said affected customers would be contacted through official channels for clarification and individualized support. [2]
Timeline
Documented event
HIBP BreachDate; CTT confirmed a contained incident but did not identify this date as the exact intrusion, detection, or containment date.
[1]Public disclosure
Date Renascença published CTT’s direct response.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
Response
CTT described an external exposure of data associated with the Locky locker network and said the related security incident had been contained. CTT said Portugal’s National Cybersecurity Centre had been notified. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]
