Capesesp Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Capesesp was listed by the Akira ransomware group on January 10, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of individuals may have been affected; anyone connected to the organisation should verify their status and review steps to protect their information.
People whose personal and employment records sit with Capesesp, a Brazilian closed supplementary pension fund, may now face the practical risk that sensitive documents have left the organisation’s control. On 10 January 2025 the ransomware group akira listed Capesesp on its leak site and claimed to hold more than 90 GB of internal files ready for publication. The number of individuals affected remains unknown, yet the types of material the group says it possesses—identity papers, medical records, contact details—carry lasting consequences for identity theft, fraud and privacy loss.
Public detail is limited to the listing itself and the group’s description of the material. No independent confirmation of the volume, the exact files, or the method of intrusion has been released. For anyone who has ever been an employee, beneficiary or customer of Capesesp, the immediate question is whether their own data sits inside that claimed cache and what steps they can take while the situation remains unclear.
Inside the incident
According to the available record, Capesesp was listed by the akira ransomware group on 10 January 2025. The group stated that it had exfiltrated internal files during a ransomware attack and was prepared to upload more than 90 GB of private corporate documents. The listing characterises Capesesp as the National Health Foundation Employee Pension and Assistance Fund, a closed supplementary pension entity sponsored by the National Health Foundation (FUNASA).
No further technical detail—how the attackers gained access, when the intrusion began, whether systems were encrypted, or whether any ransom demand was met—has been disclosed in the public record. The number of people whose data may be involved is listed as unknown. The only concrete claim about content comes from the group itself: HR documents, contact numbers and e-mail addresses of employees and customers, INSS numbers, personal identity cards, confidential corporate documents, employee medical documents and birth certificates, among other materials. These assertions remain unverified claims made on the leak site.
Who is akira?
Akira is a ransomware operation that emerged in early 2023 and has since targeted organisations across multiple sectors and countries. The group typically employs a double-extortion model: after gaining access it both encrypts systems and steals data, then threatens to publish the stolen material if a ransom is not paid. Listings on its dedicated leak site serve as public pressure and as proof of possession. Akira has been observed using common initial-access techniques such as compromised credentials or unpatched remote-access services, followed by lateral movement and large-scale data exfiltration. The group’s public claims about any single victim, including Capesesp, should be treated as assertions rather than What's Publicly Reported unless independently verified.
About Capesesp
Capesesp operates as a closed supplementary pension and assistance fund for employees linked to Brazil’s National Health Foundation (FUNASA). Entities of this type manage retirement benefits, health-related assistance and associated administrative records for a defined population of public-sector workers and their dependants. Because the fund handles both financial entitlements and personal welfare matters, it routinely processes identity documents, employment histories, medical information and contact data. A breach involving such an organisation therefore touches records that are both long-lived and highly personal, raising stakes for the individuals who rely on the fund for pensions and assistance.
What data was at risk
The public record states only that internal files were exfiltrated in a ransomware attack. The akira group claims the material exceeds 90 GB and includes HR documents, employee and customer contact numbers and e-mail addresses, INSS numbers, personal identity cards, confidential corporate documents, employee medical documents and birth certificates. These specific categories are the group’s own description; they have not been independently confirmed. Organisations that administer employee pension and assistance funds typically hold precisely these kinds of records—identity proofs, medical files, payroll and contribution data, and correspondence—so the claimed contents align with the data such an entity would be expected to possess. Exact file inventories, the total number of individuals represented, and whether any particular person’s records are present remain unconfirmed.
Why it matters
If the claimed documents are authentic and later published or sold, affected individuals face concrete risks: identity fraud using official identity cards and birth certificates, social-engineering attacks that exploit real contact details and employment history, and exposure of medical information that can lead to discrimination or targeted scams. INSS numbers and pension-related data can be misused to redirect benefits or open fraudulent accounts. For Capesesp itself, the incident raises operational, legal and reputational questions around the safeguarding of beneficiary information, even though no determination of fault has been established in the public record. Because the number of people affected is unknown, the full scale of potential harm cannot yet be measured, but the sensitivity of the data types claimed makes the episode consequential for anyone whose records may be involved.
What to do if you're exposed
Anyone who has been an employee, beneficiary or customer of Capesesp should treat the possibility of exposure seriously. Monitor bank and pension statements for unexpected activity, place fraud alerts with credit bureaus where available, and be alert to phishing or social-engineering attempts that reference personal or employment details. Change passwords on any accounts that may have shared credentials with Capesesp-related systems, and enable multi-factor authentication wherever possible. If identity documents appear among the claimed files, consider requesting replacement documents through official channels. Readers can also run a free exposure scan of their e-mail address to check whether that address has already appeared in known breach data sets; such a scan provides an early indicator but does not cover every possible record. Continue to follow official statements from Capesesp or Brazilian data-protection authorities for any confirmed guidance or notification process.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Réseau Radiologique Romand Listed by akira Ransomware GroupNickman, DHK Architects, Profondia, Talbot & Associates, Fishbowl Solutions. Listed by akira Ransomware GroupConsolidated Sterilizer Systems Listed by akira Ransomware GroupProgressive Laboratories Listed by akira Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Capesesp Listed by akira Ransomware Group →
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.