Brazil’s Logar hit by VEXY ransomware
Security Arsenal confirmed Logar Network Solutions in Brazil as a new VEXY victim. Breach House and Ransomware.live tied it to MSP services.
Security Arsenal confirmed a new VEXY Ransomware victim post for Logar Network Solutions, a Brazilian company, between September 9 and 12, 2026. The firm placed it in technology and IT network infrastructure services, while Breach House and Ransomware.live linked it to the MSP ecosystem.
Security Arsenal confirmed a new VEXY Ransomware victim post for Logar Network Solutions, a company based in Brazil, within the September 9 to 12, 2026 window. The company was placed by the source in the technology sector, with a focus on network services and IT infrastructure, and the case fits a pattern of targets tied to technology providers.
What did Security Arsenal say about the case?
Security Arsenal described Logar Network Solutions as part of a series of VEXY victims that included technology and network infrastructure organizations. In its analysis, the group’s initial access pattern pointed to the exploitation of edge devices, with a victim profile consistent with exposed devices taken advantage of opportunistically, rather than focused social engineering aimed at a specific region.
The same source framed the incident as part of a campaign with several technology-sector victims over a few days. In that context, Logar Network Solutions reinforces the view of an attack aimed at exposed services, not at a sector chosen solely because of geography.
How did other sources classify it?
Breach House listed Logar Network Solutions as a VEXY target with Brazil as the country and the leak status pending. In its taxonomy, it placed the company under Services and expanded its profile as a managed IT services provider, with offerings that include IT management, cybersecurity, cloud infrastructure, backup, software, and custom development.
Ransomware.live also recorded it as a VEXY Ransomware victim with a discovery date of 2026-09-09. There, it identified the company more specifically as a Brazilian MSP focused on IT management, cybersecurity, cloud infrastructure, backup and disaster recovery, software licensing, and hardware lifecycle management.
What is the scope of attribution in Brazil?
The available material does not support claiming a broad campaign in Brazil with enough independent confirmation. It does show at least one other Brazilian organization in Ransomware.live’s victim map, Engefitas, listed as a VEXY victim with a discovery date of 2026-09-03 and an estimated attack date of 2026-09-02.
That second record raises the possibility of more than one Brazilian target in the group’s timeline. Even so, the available information does not add technical detail about the attack vector or confirm a Brazil-specific campaign pattern.
Sources
- 553 victims for Brazil - Ransomware.liveransomware.live· Ransomware.live
- Vexy ransomwareransomware.live· Ransomware.live
- VEXY Ransomware Gang: 3 Technology Sector Victims in 5 Days ...securityarsenal.com· Security Arsenal
- Vexy Ransomware ransomware group - Discover all the ...breach.house· Breach House



