CiberLATAMbywhalemate

Brazil Shows Up Again on Leak Sites

IntelFusions logged 68 leak site claims against South American organizations in 30 days, including cases in Brazil.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

IntelFusions recorded 68 leak site claims against South American organizations in the 30 days through Aug. 8, 2026. Nine of them named government or education entities, with several in Brazil. Separately, SecurityArsenal reported a Brazilian victim linked to Direwolf in a burst of 10 victim postings in 24 hours.

IntelFusions recorded 68 leak site claims against South American organizations in the 30 days through Aug. 8, 2026. Nine of those named a government or educational entity, and several were concentrated in Brazil. Among the reported cases were a claim by The Gentlemen against the Municipal Chamber of Serra, in Espírito Santo, and another by Krybit against CESMAC University Center.

What Brazilian cases did IntelFusions report?

IntelFusions reported two specific claims in Brazil and at least two Brazilian wins attributed to L Group, according to its own leak site monitoring. The firm said The Gentlemen posted a claim against the Municipal Chamber of Serra, in the Brazilian state of Espírito Santo, dated July 31, 2026, and Krybit posted another against CESMAC University Center, in Brazil, on Aug. 4, 2026.

The same source also said that, among the South American claims it observed, there were at least two Brazilian wins attributed to L Group, based on its own leak site monitoring.

What did SecurityArsenal observe about Direwolf?

SecurityArsenal reported that Direwolf posted one Brazilian victim, Chat Jurídico, as part of a wave of 10 new victim postings in 24 hours. The firm's analysis described tactics that included exploiting publicly exposed applications, external remote services, command interpreter execution, WMI, obfuscation, file deletion and recovery inhibition, along with encryption for impact.

Taken together, the two reports show Brazil exposed across municipal and education sectors, while Direwolf also added a local victim to its public list. The threat intelligence sources point to an operation built around access to exposed services and actions designed to make response and restoration harder.

Sources

View all