---
title: "CTT Locky customer-data incident"
description: "Evidence-backed account of CTT Locky customer-data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/ctt-locky-customer-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/ctt-locky-customer-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/ctt-locky-customer-data-incident-2026/stix.json"
---

# CTT Locky customer-data incident

CTT confirmed a contained security incident associated with external exposure of Locky smart-locker-network data. Contact data associated with Locky delivery notifications and a separately quantified verified HIBP email corpus.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Locky smart-locker network
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

[CTT](https://www.ctt.pt/) confirmed a contained security incident associated with external exposure of Locky smart-locker-network data. [2](#source-2)

## Impact

Contact data associated with Locky delivery notifications and a separately quantified verified HIBP email corpus. [1](#source-1) [2](#source-2)

Documented data types include:

- Contact information — CTT described delivery-notification contact data; HIBP lists email addresses and phone numbers for the verified corpus. [1](#source-1) [2](#source-2)
- Names — Names listed in the HIBP DataClasses for the verified corpus. [1](#source-1) [2](#source-2)

A cited record reports 468,124 records (Unique email addresses represented in the verified HIBP corpus; not a CTT-confirmed number of customers, parcels, accounts, or affected people; as of 2026-05-19). [1](#source-1) [2](#source-2)

CTT said the exposed data did not include full addresses, passwords, or financial data. [2](#source-2)

CTT said affected customers would be contacted through official channels for clarification and individualized support. [2](#source-2)

## Timeline

### April 26, 2026 — Documented event

HIBP BreachDate; CTT confirmed a contained incident but did not identify this date as the exact intrusion, detection, or containment date. [1](#source-1)

### April 27, 2026 — Public disclosure

Date Renascença published CTT's direct response. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The incident involved Locky smart-locker network. [2](#source-2)

CTT said the Locky system was not compromised and remained operational. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

CTT described an external exposure of data associated with the Locky locker network and said the related security incident had been contained. CTT said Portugal's National Cybersecurity Centre had been notified. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/ctt-locky-customer-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### CTT breach record

advisory · Have I Been Pwned · May 19, 2026

<https://haveibeenpwned.com/api/v3/breach/CTT>

<a id="source-2"></a>

### CTT confirma roubo de dados de clientes

news · Renascença · Apr 27, 2026

<https://rr.pt/noticia/economia/2026/04/27/ctt-confirma-roubo-de-dados-de-clientes/468636/>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exposed Record Count · 100% confidence · current**  
   CTT Locky delivery-notification contact-data corpus: 468,124 record
2. **Resulted In · 100% confidence · current**  
   April 2026 CTT Locky data breach: CTT described an external exposure of data associated with the Locky locker network and said the related security incident had been contained.
3. **Resulted In · 100% confidence · current**  
   CTT Locky delivery-notification contact-data corpus: CTT said the exposed data did not include full addresses, passwords, or financial data.
4. **Resulted In · 100% confidence · current**  
   April 2026 CTT Locky data breach: CTT incident notifications
5. **Affected Organization · 100% confidence · current**  
   April 2026 CTT Locky data breach: CTT – Correios de Portugal, S.A.
6. **Disclosed At · 100% confidence · current**  
   April 2026 CTT Locky data breach: 2026-04-27
7. **Resulted In · 100% confidence · current**  
   CTT incident notifications: CTT said Portugal's National Cybersecurity Centre had been notified.
8. **Resulted In · 95% confidence · current**  
   April 2026 CTT Locky data breach: CTT Locky delivery-notification contact-data corpus
9. **Exposed Data Category · 100% confidence · current**  
   CTT Locky delivery-notification contact-data corpus: Contact information
10. **Resulted In · 100% confidence · current**  
   April 2026 CTT Locky data breach: CTT said the Locky system was not compromised and remained operational.
11. **Occurred At · 80% confidence · current**  
   April 2026 CTT Locky data breach: 2026-04-26
12. **Used Product · 100% confidence · current**  
   April 2026 CTT Locky data breach: Locky smart-locker network
13. **Exposed Data Category · 100% confidence · current**  
   CTT Locky delivery-notification contact-data corpus: Names
14. **Resulted In · 100% confidence · current**  
   CTT incident notifications: CTT said affected customers would be contacted through official channels for clarification and individualized support.

</details>
