Brazil Was Section9’s Main Ransomware Target
Section9 listed multiple Brazilian victims on July 26, 2026. Breach and exfiltration claims remain unconfirmed.
Section9 was recorded on July 26, 2026 across several threat intelligence platforms as a ransomware group targeting Brazilian organizations. In some cases, the listings included claims of data exfiltration that have not been confirmed by the affected entities or official agencies.
Section9 was recorded on July 26, 2026 across several threat intelligence platforms as a ransomware group active against Brazilian organizations. In some cases, the listings included claims of data exfiltration that have not been confirmed by the affected entities or by official agencies.
What Breach House recorded
Breach House lists Section9 as a group with 36 published victims. In its dataset, Brazil appears as the most affected country, with 12 victims. The same portal also shows an incident record in which Section9 claims a ransomware attack against a ****.com.br domain in Brazil, with both the discovery date and the publication date of the listing set for July 26, 2026.
Listings tied to Brazilian domains
GalaxyWarden reported that the Brazilian domain *******.net.br appeared on Section9's leak site on July 26, 2026, and said it allegedly pointed to a ransomware operation involving exfiltrated internal files. The platform also states that it did not independently verify the breach or the accuracy of the group's claims.
RecentBreaches, meanwhile, says Section9 listed several Brazilian domains as victims on that same day, including *******.net.br, ********.com.br and *****.ind.br. The portal notes that these are listings on Section9's leak site and not independent breach confirmations.
Scope across ransomware maps
The ransomware.live portal records multiple victims associated with Section9 with a discovery date of July 26, 2026. That set includes several .br domains among the most affected countries, and some are classified in sectors such as agriculture, fintech, telecommunications, cybersecurity and media. In its Brazil map, ransomware.live includes victims located in the country and identifies Section9 among the groups that have listed Brazilian organizations as affected within a broader set of incidents.
Dexpose.io also reported on July 26, 2026 that Section9 claimed an attack against the ********.com.br domain, described as a media organization in Brazil. According to that report, the group threatened to release sensitive data if its demands were not met, although the outlet did not publicly confirm the incident.
What remains unconfirmed
Based on the available data, Section9 appears repeatedly in different intelligence databases as an actor that placed Brazil among its main targets on July 26, 2026. Even so, the posts mentioning exfiltration, threats or attack claims remain independently unverified in the cases cited by GalaxyWarden, RecentBreaches and Dexpose.io.
Sources
- Section9 ransomware group - Discover all the information about thembreach.house· Breach House
- Group: Section9mobile.ransomware.live· ransomware.live
- Brazil ransomware incidents mapransomware.live· ransomware.live
- ******.net.br Listed by Section9 Ransomware Groupgalaxywarden.com· GalaxyWarden
- Section9: Data Breaches, Victims & Methodsrecentbreaches.com· RecentBreaches
- Section9 Launches Ransomware Attack on Brazilian Media Entitydexpose.io· Dexpose.io
- ****.com.br — SECTION9 Ransomware Attackbreach.house· Breach House



