Portugal has amended its cybercrime law to provide a legal exemption for good-faith security researchers, establishing a safe harbor for activities previously considered illegal, such as unauthorized system access or data interception. The new provision, Article 8.o-A, titled "Acts not punishable due to public interest in cybersecurity," outlines strict conditions under which security research is exempt from criminal liability, including requirements that the research aims solely to identify vulnerabilities not created by the researcher, contributes to cybersecurity, and does not seek economic gain beyond normal compensation.
Additional stipulations mandate that researchers must promptly report discovered vulnerabilities to system owners, relevant data controllers, and the CNCS, limit their actions to what is necessary for detection, avoid service disruption or data alteration, and refrain from using prohibited techniques such as DoS attacks, social engineering, or malware deployment. Any data obtained must remain confidential and be deleted within 10 days of remediation. The law also exempts acts performed with the system owner's consent, provided vulnerabilities are reported to the CNCS, thereby clearly defining the boundaries and protections for ethical hacking in Portugal.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
Portugal published Decree Law No. 125/2025 on December 4, updating its cybercrime framework to add Article 8.º-A to Law 109/2009. The change exempts certain good-faith cybersecurity research and ethical hacking activities from prosecution when strict public-interest and responsible-disclosure conditions are met.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcedatabreaches.net
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.