ANMP Breach Exposes 44,855 Portuguese Municipal Government Credentials
In August 2018, the National Association of Portuguese Municipalities (ANMP) -- the official body representing local government authorities across Portugal -- suffered a data breach that exposed the credentials of 44,855 registered users. The leaked data included email addresses alongside passwords stored in three different formats: SHA1 hashes, MD5 hashes, and in some cases, plaintext. The presence of plaintext passwords is particularly alarming, as these credentials require no cracking and were immediately usable by attackers. As a government-affiliated organization, ANMP manages sensitive institutional relationships and communications, making the exposure of its user database a matter of public interest and national security concern.
Why This Is Dangerous
Government and quasi-governmental organizations hold a position of public trust, and their databases often contain credentials used by civil servants, elected officials, municipal staff, and public sector administrators. The ANMP breach exposed passwords in multiple formats, each carrying different levels of immediate risk. Plaintext passwords could be exploited instantly. SHA1 and MD5 hashes, while slightly more protected, are both considered cryptographically weak and can be cracked rapidly using modern tools and precomputed rainbow tables. Attackers who gain access to government employee email addresses and passwords can recieve unauthorized access to not just the ANMP platform, but potentially to connected government systems, municipal networks, and intergovernmental communication channels where password reuse is common.
What Was Exposed
- Email addresses for 44,855 registered accounts
- Plaintext passwords (immediately exploitable)
- SHA1 password hashes (weak, crackable algorithm)
- MD5 password hashes (weak, widely reversible algorithm)
- User account data associated with Portuguese municipal government registrations
Why This Matters
The ANMP represents more than 300 municipalities across Portugal, making its membership database a who's-who of local government administration. Municipal officials and administrators who registered with work email addresses may have thier credentials exposed -- credentials that could provide a foothold into local government IT systems, municipal service portals, or national government communication platforms. Beyond direct system access, attackers can use this data for targeted social engineering campaigns, sending phishing emails that appear to originate from official Portuguese government addresses. The breach is also notable because it occured at an organization that facilitates inter-municipal cooperation, meaning a single compromised account could theoretically be used to impersonate trusted contacts across multiple municipalities.
How Database and Combolist Breaches Work
The ANMP breach falls into the database breach category, with the extracted data subsequently distributed as a combolist. Government and institutional websites frequently run on legacy web platforms with older codebases that may not receive timely security updates. Attackers exploit known vulnerabilities in these platforms -- such as SQL injection flaws in database-connected forms, or unpatched content management systems -- to extract user tables. The ANMP's use of SHA1, MD5, and even plaintext password storage reflects the security standards of the era, but these standards were already considered inadequate by 2018. Once extracted, the data is structured as email:password pairs and circulated on criminal forums, where it is incorporated into large aggregated combolists used in automated credential stuffing attacks. Government agency breaches are particularly valued in these markets because the associated email domains often bypass basic spam filters and trust heuristics on corporate platforms.
Check If You Are Affected
If you ever registered an account on the ANMP website at anmp.pt, your credentials may have been included in this breach. Take the following steps to protect yourself:
- Change your ANMP password immediately and update any matching passwords used on other platforms, especially government or institutional accounts
- Visit Have I Been Pwned and enter your email address to check if it appears in this breach or others
- Enable two-factor authentication (2FA) on all accounts that support it, with priority given to email and government service portals
- Use a password manager to generate and maintain unique passwords for every service you use
- Report any suspicious login activity to your organization's IT security team immediately
- Be alert to phishing emails that may appear to come from Portuguese municipal authorities or government bodies
Breach Breakdown
44,855 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds