CiberLATAMbywhalemate

Brazil Was Section9’s Main Ransomware Target

Section9 listed multiple Brazilian victims on July 26, 2026. Breach and exfiltration claims remain unconfirmed.

Whalemate Labs · AI-assisted researchJul 31, 20262 min read

Section9 was recorded on July 26, 2026 across several threat intelligence platforms as a ransomware group targeting Brazilian organizations. In some cases, the listings included claims of data exfiltration that have not been confirmed by the affected entities or official agencies.

Section9 was recorded on July 26, 2026 across several threat intelligence platforms as a ransomware group active against Brazilian organizations. In some cases, the listings included claims of data exfiltration that have not been confirmed by the affected entities or by official agencies.

What Breach House recorded

Breach House lists Section9 as a group with 36 published victims. In its dataset, Brazil appears as the most affected country, with 12 victims. The same portal also shows an incident record in which Section9 claims a ransomware attack against a ****.com.br domain in Brazil, with both the discovery date and the publication date of the listing set for July 26, 2026.

Listings tied to Brazilian domains

GalaxyWarden reported that the Brazilian domain *******.net.br appeared on Section9's leak site on July 26, 2026, and said it allegedly pointed to a ransomware operation involving exfiltrated internal files. The platform also states that it did not independently verify the breach or the accuracy of the group's claims.

RecentBreaches, meanwhile, says Section9 listed several Brazilian domains as victims on that same day, including *******.net.br, ********.com.br and *****.ind.br. The portal notes that these are listings on Section9's leak site and not independent breach confirmations.

Scope across ransomware maps

The ransomware.live portal records multiple victims associated with Section9 with a discovery date of July 26, 2026. That set includes several .br domains among the most affected countries, and some are classified in sectors such as agriculture, fintech, telecommunications, cybersecurity and media. In its Brazil map, ransomware.live includes victims located in the country and identifies Section9 among the groups that have listed Brazilian organizations as affected within a broader set of incidents.

Dexpose.io also reported on July 26, 2026 that Section9 claimed an attack against the ********.com.br domain, described as a media organization in Brazil. According to that report, the group threatened to release sensitive data if its demands were not met, although the outlet did not publicly confirm the incident.

What remains unconfirmed

Based on the available data, Section9 appears repeatedly in different intelligence databases as an actor that placed Brazil among its main targets on July 26, 2026. Even so, the posts mentioning exfiltration, threats or attack claims remain independently unverified in the cases cited by GalaxyWarden, RecentBreaches and Dexpose.io.

Sources

View all