createinfor.pt Listed by m3rx Ransomware Group: What Was Exposed & What To Do
createinfor.pt has been listed by the m3rx ransomware group, with internal files reported exfiltrated in an attack disclosed on July 26, 2026. Individuals and organisations connected to createinfor.pt should verify whether their data was exposed and take appropriate protective steps.
On July 26, 2026, the Portuguese repair-services firm createinfor.pt was listed by the ransomware group m3rx. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further specifics about timing, method, and exact contents have not been disclosed.
For a small company handling customer and operational records, any confirmed or claimed exposure of internal files raises practical concerns for clients, staff, and partners. What is known so far is limited to the group’s listing and the high-level description of stolen internal material; independent confirmation of the full scope is not part of the public record.
Inside the incident
According to the available facts, createinfor.pt appeared on a m3rx listing dated July 26, 2026. The reported summary describes the incident as a ransomware attack in which internal files were exfiltrated. No figure has been given for the volume of data, no file names or categories beyond “internal files” have been published in the facts, and the number of affected individuals is listed as unknown. The method of initial access, the duration of any intrusion, and whether systems were encrypted in addition to data theft are undisclosed.
The listing itself constitutes a claim by the group. Public detail does not confirm whether negotiations occurred, whether a ransom was demanded or paid, or whether the data has been released beyond the initial assertion of exfiltration. Stolen-data fields in the report are marked as unavailable. Readers should treat the incident as an unverified claim of compromise until additional independent reporting appears.
Who is m3rx?
m3rx is a ransomware group known publicly for double-extortion tactics: encrypting victim systems while also copying data and threatening to publish it on a leak site if demands are not met. Like other groups operating in this model, m3rx typically posts victim names, sometimes with sample files or descriptions, to pressure organisations. Prior public activity associated with the name has followed the familiar pattern of leak-site announcements rather than quiet, private extortion alone.
In this case, the group claims createinfor.pt as a victim and asserts that internal files were taken. No statements attributed to m3rx beyond that listing appear in the facts provided. Claims made on criminal leak sites are not independent verification; they are assertions that require corroboration from the organisation, regulators, or forensic reporting.
Who is createinfor.pt?
CreateInfor (createinfor.pt) is described as a company in the repair-services industry, headquartered in Caldas da Rainha, Leiria, Portugal. Public summary information places it in the 10-to-19 employee range with estimated revenue between 500,000 and 1 million (currency not further specified in the facts). A contact telephone number associated with the firm is given as +351 262187684.
Organisations in repair services commonly manage customer contact details, equipment or job records, invoices, supplier information, and internal operational files. Even a modest headcount does not eliminate the sensitivity of that material. A breach affecting such a firm can touch local customers and small-business partners who may have little visibility into how their data is stored or protected. The consequential aspect is not the company’s size but the trust placed in it to handle service-related personal and commercial information.
What data was at risk
The facts name the exposed material only as “internal files exfiltrated in ransomware attack.” No further breakdown—customer databases, employee records, financial documents, or credentials—is supplied. The “Stolen” field in the source summary is blank. Exact contents therefore remain unconfirmed.
Companies of this type typically hold names, phone numbers, addresses, service histories, payment or invoice data, and internal correspondence. It is reasonable to expect that some mixture of those categories could have been among internal files, but it is not established fact that any specific category was taken. Until createinfor.pt or an official investigation publishes a clearer inventory, the public record supports only the general claim of internal-file exfiltration.
The real-world impact
For individuals whose details may have been inside those files, risks include unwanted contact, phishing that references real service history, and misuse of personal or billing information. Because the scale is unknown, it is impossible to say how many people sit in that category. For the organisation, a ransomware incident can mean operational disruption, recovery costs, regulatory notification duties under applicable European rules, and reputational harm with customers who rely on repair services.
Impact is concrete rather than abstract: time spent resetting access, monitoring accounts, and answering customer questions, plus the possibility that copied files could surface later on criminal forums. None of these outcomes is confirmed as having already occurred solely from the listing; they are the ordinary consequences that follow when internal files are claimed to have left an organisation’s control.
What to do if you're exposed
If you have been a customer, employee, or partner of createinfor.pt, treat the situation as a prompt for ordinary hygiene rather than panic. Practical first steps include:
- Watch for unexpected messages that reference repairs, invoices, or personal details you shared with the firm; verify any request through a known official channel before responding.
- Change passwords on accounts that may have reused credentials connected to the company, and enable multi-factor authentication where available.
- Review bank and card statements for unfamiliar charges if you provided payment information for services.
- Keep records of any suspicious contact and report clear fraud attempts to local authorities or your bank.
- Run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets.
Public detail on this incident remains limited. Further clarity, if it comes, will most likely arrive from the company itself or from official notices. Until then, measured caution with personal data and routine account monitoring are the proportionate responses.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
servicebypremier.com Listed by m3rx Ransomware Groupausproof.com.au Listed by m3rx Ransomware Grouphydraulic-components.net Listed by m3rx Ransomware Groupubfreight.com Listed by m3rx Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the createinfor.pt Listed by m3rx Ransomware Group →
Publicly posted by m3rx — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.