LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › FMZ Tecnologia em Sistemas Listed by nova Ransomware Group

HIGH severityUnverified claimHow we verify

FMZ Tecnologia em Sistemas Listed by nova Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 18, 2026
FMZ Tecnologia em Sistemas Listed by nova Ransomware Group

Reported July 18, 2026.

HIGH
Severity
1
Data types exposed
July 18, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

FMZ Tecnologia em Sistemas was listed by the nova ransomware group on July 18, 2026, with internal files reported as exfiltrated. Individuals are advised to check whether their information was exposed and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the FMZ Tecnologia em Sistemas Listed by nova Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

On July 18, 2026, the ransomware group known as nova listed FMZ Tecnologia em Sistemas, a Brazilian software company, among the organizations it claims to have attacked. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and wider technical details have not been disclosed.

Because FMZ builds industry-specific software used by publishers, bookstores, and distributors, any confirmed exposure of internal material could affect not only the company but also the business partners and operational data that flow through its systems. At this stage, the listing itself is a claim by the group rather than an independently verified public confirmation of every asserted detail.

Breaking down the breach

According to the available record, FMZ Tecnologia em Sistemas was named on nova’s leak-site activity with a reported date of July 18, 2026. The incident is described as a ransomware attack in which internal files were exfiltrated. No public figure has been given for the volume of data, the number of systems involved, or the count of individuals whose information may have been touched.

Method of initial access, dwell time, ransom demand, and whether encryption was deployed alongside theft are undisclosed in the facts provided. Likewise, there is no confirmed public inventory of exact file names, databases, or customer records. What is stated is limited to the organization’s listing by the group and the characterization that internal files were taken during a ransomware incident. Until the company or independent investigators publish further findings, scale and full scope remain unconfirmed.

Who is nova?

Nova is a ransomware group that operates in the familiar double-extortion model used by many contemporary actors: data is stolen, systems may be encrypted, and victims are pressured with the threat of public release if demands are not met. Such groups typically maintain leak sites or similar channels where they name organizations and, in some cases, sample or dump material to demonstrate access.

Public reporting on nova and peer groups has generally described opportunistic and targeted intrusions against businesses across multiple sectors and countries, often relying on compromised credentials, exposed remote services, or other common entry points before moving laterally and staging exfiltration. Those patterns are drawn from the broader public record of the actor’s class of activity; they are not specific forensic findings about the FMZ case. Regarding this incident, the group’s listing of FMZ Tecnologia em Sistemas should be treated as its claim. No additional statements attributed to nova about this victim beyond that listing are included in the facts at hand.

About FMZ Tecnologia em Sistemas

FMZ Tecnologia em Sistemas is a Brazilian software company based in São Paulo, with more than fifteen years of experience developing solutions for the book industry. Its principal product, HORUS, is an ERP system built for publishers, bookstores, and distributors. The platform is used to manage inventory, sales, royalties, and consignment operations—core commercial processes in publishing and bookselling supply chains.

Organizations that supply vertical ERP software sit at a sensitive intersection: they hold their own corporate data and, by design, process or connect to operational and commercial information belonging to clients. A breach affecting such a provider can therefore raise questions not only about the vendor’s internal environment but also about trust, continuity, and data-handling obligations across the publishers, retailers, and distributors that rely on the software. The consequential nature of an incident here stems from that sector role rather than from any publicly established finding of fault.

The information in question

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as whether the files included source code, customer databases, employee records, financial documents, or client operational data—has been disclosed in the available record. The number of people affected is unknown.

Companies of this type commonly hold employee and contractor information, commercial contracts, system configuration and support data, and, depending on architecture and hosting arrangements, varying degrees of client-related business data tied to inventory, sales, royalties, or consignments. Those are general expectations for a book-industry ERP vendor; they are not a confirmed inventory of what nova obtained. Exact contents remain unconfirmed, and no specific data categories beyond “internal files” should be treated as established fact.

Why it matters

For individuals, the practical risk depends entirely on what was actually taken—an unknown at present. If employee or partner personal data were among the internal files, affected people could face phishing, identity misuse, or unwanted contact that leverages exposed details. If client business data were involved, publishers and booksellers might confront commercial confidentiality concerns, disruption to royalty or inventory processes, or secondary social-engineering attempts aimed at their staff.

For FMZ, a ransomware event with claimed exfiltration raises operational, legal, and reputational stakes: restoring systems, assessing contractual notice duties, supporting clients, and hardening the environment against repeat intrusion. Because the company’s software supports day-to-day commerce in the book trade, prolonged uncertainty about what left the network can erode confidence even before full technical findings are public. None of these risks require assuming negligence; they follow from the ordinary consequences of ransomware and data theft claims against a sector software provider.

Were you affected?

If you are an employee, contractor, client contact, or partner of FMZ Tecnologia em Sistemas, treat unsolicited messages that reference the company, invoices, royalties, or system access with caution until more is known. Prefer official channels the company has used in the past, enable multi-factor authentication on related accounts, and monitor financial and email accounts for unusual activity. Keep records of any suspicious contact.

Public detail on this incident remains limited: people affected are unknown, and only internal files have been named at a high level. You can run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets, which may help you decide what to secure next while waiting for any formal notices.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyFMZ Tecnologia em Sistemas security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See FMZ Tecnologia em Sistemas’s full breach history →

More recent breaches

Digital Edge Listed by nova Ransomware GroupJuly 24, 2026Marpatech Listed by nova Ransomware GroupJuly 22, 2026Jota Joias Premium Listed by nova Ransomware GroupJuly 19, 2026Vnso Listed by nova Ransomware GroupJuly 22, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the FMZ Tecnologia em Sistemas Listed by nova Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by nova — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram