惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
博客园 - Franky
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
有赞技术团队
有赞技术团队
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
阮一峰的网络日志
阮一峰的网络日志
C
Check Point Blog
爱范儿
爱范儿
T
The Blog of Author Tim Ferriss
aimingoo的专栏
aimingoo的专栏
Stack Overflow Blog
Stack Overflow Blog
博客园 - 聂微东
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LangChain Blog
云风的 BLOG
云风的 BLOG
MyScale Blog
MyScale Blog
Microsoft Security Blog
Microsoft Security Blog
The Cloudflare Blog
博客园 - 三生石上(FineUI控件)

The Register - Special Features

23andMe inherits lawsuit over 'disturbing' DNA data breach Troops’ phones gave away location data to foreign adversaries Qualcomm picks bad time to pitch a $300 laptop platform AI agents get their own phone directory built atop DNS Carnival confirms ShinyHunters cruised off with 6M customer records after April breach Google engineer accused of turning Year in Search secrets into Polymarket payday Are we human? India's cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat Broadcom gets early start on WiFi 8 with next-gen wireless routing kit Are we human? Microsoft Excel champ proves he still has the formula Anthropic co-founder hallucinates ghost in the machine Anthropic co-founder hallucinates ghost in the machine NASA plans Moon Base buildout with rovers, drones, cargo landers MyPillow must decide whether to be firm or soft as ransomware crims demand pay Starship shows it can deploy satellites, but Moon mission clock still ticks Huawei's chip law looks less like Moore and more like marketing Experts pour cold borscht on Farage's Russian hack claim Logitech unveils a cushioned mouse for all-day use AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets AI datacenter boom collides with US grid reality Media giant settles for $930k amid user-snooping allegations AT&T sues to ditch Cali copper phone lines to save billions FBI warns of Kali365 as device code phishing soars Techie claims Trump Mobile website was leaking thousands of people's data BOFH: Vibe-coded solutions arrive for problems nobody has Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Google explains how it will infuse ads into AI answers AI is getting pricey, but relief is coming, but not for you
468k records allegedly stolen from Portugal’s postal carrier
2026-05-19 · via The Register - Special Features

Cyber-Crime

Crook leaks 468k+ records, claims they pwned Portugal’s postal carrier

Ordered packages via CTT? Those phishing emails could be tricky to spot

Data allegedly belonging to CTT, the operator of Portugal’s national postal service, has leaked online, affecting hundreds of thousands of individuals.

According to HaveIBeenPwned, which ingested the data, a little more than 468,000 unique email addresses were included in the vast data dump, along with full names, phone numbers, and parcel tracking codes that could be used to identify different locations along a package’s journey.

In 2026, many people now assume that their basic personal data has been included in a data breach or two, and that it can be bought online.

REG AD

However, when data breaches include details such as parcel tracking codes alongside basic personal information – the type that isn’t typically part of every breach – it can provide cybercriminals with crucial information to conduct convincing phishing campaigns.

REG AD

Fake parcel emails and SMS messages become all the more convincing if the attacker behind them can persuade the target that they possess information only the spoofed organization could hold.

The stolen data was leaked on April 27, according to cybercrime forum watchers, by a hacker calling themselves “Boogeyman.”

HaveIBeenPwned confirmed the breach on Tuesday, putting the scale significantly below what Boogeyman had claimed weeks earlier. While the data types matched, the crook alleged over one million customer records were exposed, more than double the 468k+ verified by HaveIBeenPwned. 

In addition, the criminal claimed to have stolen technical data regarding the company’s 24/7 postal lockers provided by its Locky brand. Supposedly included among these were locker configurations, private IPs, machine types, locker IDs, and backend versions. 

HaveIBeenPwned only summarised the consumer-related data, not the technical side of it, and The Register neither downloaded nor examined the raw data.

To date, CTT has not publicly acknowledged the alleged cyberattack that led to the data breach. 

The Register approached the company for a statement but it did not immediately respond. ®