LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Brasilmad Listed by sarcoma Ransomware Group

HIGH severityUnverified claimHow we verify

Brasilmad Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 12, 2024
Brasilmad Listed by sarcoma Ransomware Group

Reported December 12, 2024.

HIGH
Severity
December 12, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On December 12, 2024, the Brasilmad ransomware incident was publicly listed by the sarcoma group, which claims to have exfiltrated internal files from the organisation. Individuals who may have had dealings with Brasilmad should review any notifications from the company and consider protective steps such as monitoring accounts and changing passwords.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On December 12, 2024, the Brazilian wood-export company Brasilmad was listed by the ransomware group sarcoma as a victim of a ransomware attack in which internal files were claimed to have been exfiltrated. Public reporting does not state how many people were affected, the precise method of intrusion, or a confirmed inventory of the files taken. What is known so far is limited to the group's leak-site listing and the description of the incident as a ransomware attack involving internal-file exfiltration.

For an organisation that has operated in the international timber trade since 1997, any confirmed compromise of internal systems raises practical questions about operational continuity, contractual partners, and the personal or commercial data that such businesses routinely process. Until independent verification appears, the listing remains an unverified claim by the group.

Breaking down the breach

According to the available record, Brasilmad was listed by sarcoma on December 12, 2024. The incident is described as a ransomware attack in which internal files were allegedly exfiltrated. No public figure has been given for the number of people affected, no date of initial intrusion has been disclosed, and no technical details of the attack vector have been released. The record does not confirm whether systems were encrypted, whether a ransom demand was made, or whether any data has been published beyond the listing itself. In short, the concrete facts remain the listing date, the attribution to sarcoma, and the characterisation of the event as ransomware with internal-file exfiltration.

The group behind it: sarcoma

Sarcoma is a ransomware operation that has appeared in public threat reporting as a double-extortion actor: it encrypts systems and simultaneously claims to steal data, then pressures victims by threatening to publish the material on a dedicated leak site. Like other groups of this type, it typically posts victim names, sometimes with sample files or brief descriptions, to demonstrate access and to increase leverage. Public knowledge of sarcoma does not include any independently verified statement about Brasilmad beyond the listing itself. Therefore the claim that Brasilmad suffered a ransomware attack with internal-file exfiltration should be treated as an assertion by the group until corroborated by the company, regulators, or forensic investigators.

Who is Brasilmad?

Brasilmad is a Brazilian corporation active in the wood-export market since 1997. It specialises in pine wood cut and processed to client specifications and supplies material used in furniture manufacture, special packaging and construction across multiple continents. The company maintains partnerships with sawmills that operate their own forests; one principal partner is Imaribo S/A Ind e Com, described as one of the larger Brazilian sawmills with approximately 13 000 hectares of pine forest. It is presided over by Nivaldo Dzyekanski, an entrepreneur with experience in the wood-export sector. Organisations of this kind typically hold commercial contracts, shipping and customs documentation, supplier and customer contact details, employee records, and financial data. A breach at such a firm can therefore affect both business partners and individuals whose information appears in those records, even when the exact contents of any stolen files remain unconfirmed.

What data was at risk

The public record states only that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, volumes or categories has been disclosed. Companies operating in timber export commonly maintain customer and supplier databases, logistics and customs paperwork, employee personnel files, financial ledgers and internal correspondence. Whether any of those categories were among the files allegedly taken from Brasilmad is unconfirmed. Readers should therefore treat the exposure as limited to the general claim of “internal files” until more precise inventories appear.

The real-world impact

For individuals whose data may have been present in internal systems, the principal risks are identity misuse, targeted phishing that references genuine commercial relationships, and possible exposure of personal contact or employment details. For Brasilmad itself, the consequences can include operational disruption, contractual disputes with overseas buyers, regulatory scrutiny under Brazilian data-protection rules, and reputational damage among long-standing partners. Because the number of people affected remains unknown and the precise contents of the files are undisclosed, the scale of these risks cannot yet be quantified. The listing alone, however, is sufficient to warrant heightened vigilance by anyone who has done business with or worked for the company.

What to do if you're exposed

If you have a past or present connection to Brasilmad—whether as an employee, customer, supplier or contractor—consider the following practical steps:

Public detail on this incident remains limited. Further confirmed information from the company or independent investigators will be needed before a fuller picture of the exposure can be drawn.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyBrasilmad security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Brasilmad’s full breach history →

More recent breaches

Dona Formosa Listed by sarcoma Ransomware GroupJanuary 16, 2025CP Construplan Listed by sarcoma Ransomware GroupNovember 14, 2024Brancaia Listed by sarcoma Ransomware GroupOctober 31, 2024Lácteos Lorán Listed by sarcoma Ransomware GroupOctober 9, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Brasilmad Listed by sarcoma Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by sarcoma — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram