Brazil logs its busiest month on ransomware leak sites

Published

Ransomware and extortion crews named 31 Brazilian organisations on their leak sites in September, according to posts collected by the independent tracker ransomware.live. That is the most for Brazil in any single month of the tracker's dataset, and it lifted the country's share of all leak-site claims worldwide to 3.5%, against roughly 1.9% across 2025.

The pace has not let up. In the eight days from 28 September to 5 October the tracker filed ten more claims under Brazil, and at least three of them hit companies that sell IT services to other organisations.

A slow climb that turned into a step

From March to May the tracker logged 10 to 15 Brazilian claims a month. From June to September it logged 23, 26, 27 and then 31, a total of 107 in four months. Brazil's share of the global total went from 1.3% in May to 3.2% in June and 3.5% in September.

No single crew explains it. The Gentlemen accounted for seven of September's 31 Brazilian claims, LockBit and Emperador three each, and 14 other groups shared the rest. Emperador is the crew that listed Brazil's federal tax agency last month, a claim we examined in our report on the Receita Federal listing.

Suppliers that hold other people's keys

The latest week stands out for who was named. On 28 September Emperador listed Amazon Informática, which the listing describes as an IT integrator and managed services provider founded in Brazil in 1995 whose primary market is the public sector, with offices in Brasília and Belém serving state and federal bodies. On 29 September M3rx named Soma Soluções em T.I., an ERP and corporate IT provider. On 2 October Panzer listed Paes Soluções, a business software, hosting, cloud backup and VPS company in Campo Mourão, Paraná. Two more technology firms, Softruck and Millensys, were filed under Brazil by the tracker, though we could not independently confirm where either is based.

A provider of hosting, backup or managed services usually holds remote access, credentials or copies of data that belong to its customers. If any of these claims is genuine, the organisations most exposed may be the suppliers' clients rather than the suppliers themselves.

The week also brought a public sector name. On 1 October Booba Project listed FUNAP, the Fundação Prof. Dr. Manoel Pedro Pimentel, a São Paulo state foundation on the funap.sp.gov.br domain, and said it had taken 26 GB of data. Akira named the food distributor Jampac Alimentos, RansomHouse the Espírito Santo logistics operator Terca Zilli, and LockBit the maritime services firm Camorim.

What these numbers can and cannot show

Every listing here was posted by the criminals. We found no public confirmation of an incident from any of the organisations named at the time of writing, and crews do recycle old data, inflate their hauls and occasionally list companies they never breached. The country on each post is assigned by the tracker, which sometimes misfiles a victim. Before 2024 most posts carried no country at all, so the comparison is strongest from 2024 onward, when the tracker tagged more than 90% of them. The leak sites themselves sit on .onion addresses, which we do not link; the tracker keeps a running list of Brazilian claims.

Clients of named IT providers should rotate access now

Organisations that buy hosting, backup, ERP or managed services from any of the providers named should not wait for confirmation. Review and rotate the VPN, remote management and service accounts the supplier uses, look for unexpected logins from supplier infrastructure, and ask the provider in writing whether it has investigated. Brazil's data protection law, the LGPD, requires controllers to notify the national authority, ANPD, and the people affected of a security incident that could cause them relevant risk or damage. Background on the national picture is on our Brazil country page.

One busy month could be noise. Four straight months at or above Brazil's previous monthly high of 23 look more like crews deciding the country is worth their time, and an IT supplier is the shortcut that turns one intrusion into many.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions