CiberLATAMbywhalemate

Brazil is Section9’s ransomware focus

Section9 continues to list Brazilian victims, while the breaches remain unconfirmed. Breach House now tracks 566 Brazil-linked records.

Whalemate Labs · AI-assisted researchPublished:Updated 3 min read

Section9 was listed on July 26, 2026, across several threat intelligence platforms as a ransomware group targeting Brazilian organizations, with some claims of data exfiltration still unconfirmed by affected entities and official sources.

Update September 24, 2026: Breach House expanded its country page for Brazil and now reports 566 ransomware records tied to the country, including 65 leaked cases, 500 pending, and 1 deleted. AhnLab also recorded 28 Brazil-linked cases in July 2026 in its global report, without attributing them specifically to Section9.

Section9 was listed on July 26, 2026, across several threat intelligence platforms as a ransomware group targeting Brazilian organizations. In some cases, the group claimed data exfiltration, but those claims have not been confirmed by the affected entities or by official sources.

What did Breach House record?

Breach House lists Section9 as a group with 36 published victims. In its dataset, Brazil is the most affected country, with 12 victims. The portal also shows an incident record in which Section9 claims a ransomware attack against a ****.com.br domain in Brazil, with both the discovery date and the listing date set to July 26, 2026.

In its updated country page, Breach House also reports 566 ransomware records tied to Brazil, broken down into 65 leaked cases, 500 pending, and 1 deleted. That number broadens the overall picture of the country in the database, but it does not change the lack of official verification for cases attributed to Section9.

What did the Brazilian domain listings show?

GalaxyWarden reported that the Brazilian domain *******.net.br appeared on Section9’s leak site on July 26, 2026, and said it was allegedly the result of a ransomware operation with internal file exfiltration. The platform itself says it did not independently verify the breach or the accuracy of the group’s claims.

RecentBreaches, meanwhile, says Section9 listed several Brazilian domains as victims that same day, including *******.net.br, ********.com.br, and *****.ind.br. The site notes that these are listings on Section9’s leak site, not independent breach confirmations.

What do ransomware maps show?

ransomware.live records multiple victims associated with Section9 with a discovery date of July 26, 2026. The set includes several .br domains among the most affected countries, and some are classified in sectors such as agriculture, fintech, telecom, cybersecurity, and media. In its Brazil map, ransomware.live includes victims located in the country and identifies Section9 among the groups that have listed Brazilian organizations as affected within a broader set of incidents.

Dexpose.io also published on July 26, 2026, that Section9 claimed an attack against the ********.com.br domain, described as a media organization in Brazil. According to that report, the group threatened to publish sensitive data if its demands were not met, although the outlet did not publicly confirm the incident.

How does the AhnLab data fit in?

AhnLab recorded 28 Brazil-linked cases in July 2026 in its global ransomware trends report. That figure is independent of Breach House’s database and, in the available result, is not specifically linked to Section9.

What remains open?

Based on the available data, Section9 appears repeatedly across different intelligence databases as an actor that placed Brazil among its main targets on July 26, 2026. However, the posts mentioning exfiltration, threats, or attack claims remain independently unverified in the cases cited by GalaxyWarden, RecentBreaches, and Dexpose.io.

AhnLab’s new reference adds another measure of the volume of incidents in Brazil during July 2026, but it does not resolve attribution for those cases or confirm that they belong to Section9.

Sources

View all