Meo chief joins 17 European telecoms urging overhaul of EU digital rules days after cyberattack
The chief executive of Portugal-based operator Meo has co-signed a letter with 16 other European telecoms leaders calling for a "correction of course" in two major European Union laws. The appeal, sent earlier this month, comes three days after Meo confirmed it was the target of a mass cyberattack that disrupted internet and mobile services for thousands of customers across Portugal.
Landmark EU laws
Ana Figueiredo, CEO of Meo, joined counterparts from 16 other major European telecommunications operators in sending the letter to Ursula von der Leyen, Roberta Metsola and António Costa — the presidents of the European Commission, European Parliament and European Council, respectively.
The signatories raise concerns about two landmark pieces of legislation: the Digital Networks Act (DNA) and the Cybersecurity Act (CSA). They argue that the current proposals threaten Europe's ability to maintain technological leadership and infrastructure resilience.
Attack exposed fragility
On 16 September 2026, Meo suffered a distributed denial-of-service (DDoS) attack that caused significant congestion and degradation of its international network. The incident, which the company reported to the Centro Nacional de Cibersegurança, saw the Downdetector portal register a peak of around 7,000 complaints as customers experienced difficulties accessing internet and mobile services.
Meo, the brand name for Altice Portugal, confirmed that the instability in BGP routing protocols — the system that directs traffic between networks — was a consequence of the attack, not its cause. The operator stated that the attack did not result in any intrusion into its systems or compromise of customer data.
€40 billion replacement cost
The letter from the CEOs highlights what they describe as a misalignment between Europe's competitiveness agenda and its regulatory framework. The group warns that the Cybersecurity Act's requirements for the broad removal of equipment could impose replacement costs reaching €40 billion on the sector across Europe.
The signatories argue this would drain capital precisely from the investment needed for fibre, 5G and 6G network deployment. They are calling for an approach that is proportional and based on risk, one that considers alternative mitigation measures and accounts for equipment lifecycle investments.
Investment concerns
The Digital Networks Act, as currently proposed, "does not satisfy Europe's need to substantially improve conditions for investment and innovation in connectivity," the CEOs argue. The letter outlines four priorities for legislators:
• Free up capital for network implementation.
• Promote investment driven by demand, not regulatory imposition.
• Modernise regulation for innovative networks.
• Make regulatory simplification a reality.
The group references research suggesting Europe needs an additional €475 billion in investment to achieve what they call "world-class" mobile networks. They warn that "incoherent political reforms" are jeopardising Europe's technological leadership.
New Portuguese framework
The appeal comes as Portugal adjusts to its new legal framework for cybersecurity. Decree-Law No. 125/2025, approved in December last year, transposed the EU's NIS2 Directive into Portuguese law, replacing the previous Lei n.º 46/2018. The new regime, in effect since April 2026, significantly expands obligations for operators of essential and important services.
Under the Portuguese framework, telecommunications operators are classified as essential entities and must implement technical and organisational measures to manage cybersecurity risks. The law introduces direct liability for management bodies, making cybersecurity a duty of care with potential personal consequences for board members in cases of failure.
Both the DNA and CSA are European-level legislative initiatives, whereas Portugal's national transposition of NIS2 operates separately to enforce compliance at the member-state level.
European context
Other European countries have taken differing approaches to protecting critical telecommunications infrastructure. Germany's IT Security Act 2.0 explicitly prohibits critical components from untrusted suppliers in mobile networks, while Estonia has used its Electronic Communications Act to exclude high-risk foreign suppliers from 2G to 5G networks.
France is still finalising its NIS2 implementation through its "Resilience Bill," which will also cover the DORA regulation for the financial sector. Portugal's Centro Nacional de Cibersegurança is expected to issue additional detailed regulations by June 2026.
Meo stated that services have been stabilised and it continues to coordinate with relevant entities and technology partners.
What this means for customers
For Portugal's estimated 5 million Meo customers, the incident caused temporary disruption to internet and mobile services, with no reported compromises to personal or payment data. Customers have no immediate action to take.