DDoS attack on MEO caused widespread outages in Portugal; data not compromised

MEO confirmed it was targeted by a DDoS attack that congested its international network during three distinct periods. The operator assures that there was no data access or compromise.

DDoS attack on MEO caused widespread outages in Portugal; data not compromised

MEO confirms DDoS attack after widespread outage on networks in Portugal

MEO was targeted by a distributed denial-of-service (DDoS) attack that affected its international network infrastructure during three distinct time windows, confirmed the operator in a statement sent to tek.sapo.pt newsroom. The company assures that there was no intrusion into its systems nor any access to customer data.

Portugal experienced a widespread interruption in internet and mobile network services on Monday, with impact on the four major national operators. According to Downdetector, complaints began to emerge from 17:30, reaching a peak around 18:20, and affected cities including Lisbon, Porto, Braga, Coimbra and Funchal. MEO was the most affected operator, with more than 7,000 incidents reported at the moment of greatest instability, compared with just over 300 at NOS, around 270 at Vodafone and fewer than 50 at Digi.

The incidents occurred during three specific periods: from 00:45 to 02:55, from 17:30 to 19:30, and from 22:45 to 01:05. According to the operator, all directly targeted its international network infrastructure.

Massive traffic aimed at saturating the network

As is characteristic of this type of attack, the DDoS involved high volumes of traffic with the purpose of causing congestion and temporary network degradation. The effects translated into difficulties accessing sites and services supported by international traffic for some of the operator's customers.

Through telemetry data, traffic monitoring and network indicators, MEO's teams were able to identify the nature of the attack and activate the detection, protection, mitigation and recovery mechanisms provided for such situations, which allowed the service to stabilise as quickly as possible.

Public data raised doubts about the origin

During the period of instability, public data from Cloudflare Radar and IPinfo pointed to a different scenario from an attack originating externally, fuelling various alternative theories. In light of this context, MEO clarified that the BGP routing phenomena identified were a consequence of the attack and not its cause.

According to the operator, "the instability observed at the level of BGP routings occurred in the context of the degradation caused by the attack and the operational response necessary to mitigate it". The company added that "the BGP interconnection breakdowns verified with some of the networks to which MEO is interconnected were, therefore, a consequence of the instability caused by the attack and not its cause".

No data compromise

MEO stressed that, despite the attack, there was no intrusion into its systems nor any access to or compromise of data, either of the operator or its customers. This assurance is consistent with the nature of a DDoS attack, whose primary objective is to saturate servers and not penetrate them.

As required by law, the incident was reported to the National Cybersecurity Centre (CNCS), with the operator maintaining appropriate coordination with competent authorities, technology partners and the relevant technical community for monitoring the situation.

The story was updated with additional information sent subsequently by MEO. Last update: 16:52.

Source: Google News PT

Read this article in the original language