hiway.com.br Listed by funksec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
hiway.com.br was listed by the funksec ransomware group on February 17, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; anyone who has an account or relationship with the site should review their information and monitor for signs of misuse.
In a threat landscape where ransomware groups increasingly list mid-sized infrastructure providers on leak sites to pressure payment, the appearance of a Brazilian internet-services firm has drawn attention. On February 17, 2025, the ransomware group funksec publicly claimed to have listed hiway.com.br, asserting that internal files had been exfiltrated during a ransomware attack. The number of people affected remains unknown, and independent confirmation of the full scope has not been published.
Such listings matter because internet and data-center providers sit at the intersection of customer connectivity, telephony and stored operational data. Even when exact contents stay undisclosed, the mere claim of internal-file theft raises practical questions for customers, partners and the organisation itself about what may have left the network and what residual risk remains.
What happened
According to the available record, hiway.com.br was listed by the funksec ransomware group on or around February 17, 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. Public detail does not include the precise date of intrusion, the initial access method, the volume of data taken, whether encryption was also deployed, or any ransom demand. The number of individuals or accounts potentially affected is listed as unknown. No independent verification of the group’s claims has been supplied in the source material, so the listing itself must be treated as an unverified assertion by the threat actor.
The group behind it: funksec
Funksec is a ransomware operation that became more visible in late 2024 and early 2025. Public reporting describes it as a group that practises double extortion: data is stolen before or during encryption, then victims are threatened with publication on a dedicated leak site if payment is not made. The group has been noted for relatively rapid victim listings, occasional use of AI-assisted messaging, and a willingness to target organisations across multiple sectors and geographies rather than focusing on a single industry. Like many contemporary ransomware crews, funksec appears to operate with a degree of specialisation—some members handle initial access, others manage negotiation and leak-site operations—yet concrete attribution of individual operators remains limited in open sources.
In this case the group claims hiway.com.br as a victim and states that internal files were exfiltrated. No further statements attributed specifically to this incident—such as sample file listings, screenshots of directories, or claimed ransom figures—appear in the provided facts. Therefore any description beyond the listing itself would be speculation.
About hiway.com.br
Hiway.com.br is a Brazil-based company that supplies internet connectivity packages to both individual users and larger businesses. Its public profile also includes telephony services and data-center offerings. Organisations of this type typically manage customer account records, network-configuration data, billing information, support tickets and, in the case of data-center customers, contractual and technical documentation related to hosted infrastructure. Because they sit inside the connectivity chain, a compromise can affect not only the provider’s own operations but also the availability and confidentiality of services relied upon by end users and corporate clients.
A ransomware claim against such a firm is consequential precisely because of that dual role: any disruption or data exposure can cascade to households and enterprises that depend on the provider for day-to-day connectivity and communications.
The information in question
The facts state only that “internal files” were exfiltrated in a ransomware attack. No further breakdown—customer databases, employee records, financial documents, network diagrams or otherwise—is supplied. For an internet-services and data-center operator, internal files could in principle encompass a wide range of material: configuration backups, customer-support logs, contractual paperwork, or operational documentation. Because the exact contents remain undisclosed, it is not possible to confirm which categories, if any, left the environment. Readers should treat any more specific claims circulating online as unverified unless corroborated by the organisation or by independent forensic reporting.
What's at stake
For individuals and businesses that use hiway.com.br services, the primary risks are secondary misuse of any personal or account data that may have been among the internal files, and potential service disruption if systems were encrypted or taken offline. Even when the precise data types are unknown, organisations of this kind commonly hold contact details, service identifiers and billing information; exposure of those elements can enable phishing, account-takeover attempts or social-engineering attacks that reference real account activity. For the company itself, the stakes include operational recovery costs, regulatory notification duties under Brazilian data-protection rules, and reputational damage that can affect customer retention. None of these outcomes is confirmed by the current public record; they represent the ordinary consequences that follow a claimed ransomware incident involving internal files.
Were you affected?
Because the number of people affected is unknown and the exact data types have not been itemised, individuals cannot yet determine exposure from official disclosures alone. Practical first steps remain the same regardless:
- Monitor account statements and service notifications from hiway.com.br for unexpected changes or password-reset messages that you did not initiate.
- Enable multi-factor authentication on any related email or customer portals if it is not already active.
- Treat unsolicited messages that reference the incident or demand urgent action with caution; verify them through official channels rather than links supplied in the message.
- Consider running a free exposure scan of your email address against known breach corpora to see whether that address has appeared in previously documented leaks (this will not confirm or rule out involvement in the present incident, but it can surface other exposures that warrant attention).
If hiway.com.br later publishes a formal notification or data inventory, follow the guidance it provides. Until then, the public record consists solely of the funksec listing dated February 17, 2025, and the claim that internal files were exfiltrated. Remaining attentive to official updates is the most reliable course.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
mandarin.com.br Listed by funksec Ransomware Groupmytower.com.br Listed by funksec Ransomware Groupfiberskynet.net Listed by funksec Ransomware Groupmyisp.live Listed by funksec Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the hiway.com.br Listed by funksec Ransomware Group →
Publicly posted by funksec — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.