LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Konnatus (usucapião legal services) Listed by N0n Ransomware Group

HIGH severityUnverified claimHow we verify

Konnatus (usucapião legal services) Listed by N0n Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 18, 2026
Konnatus (usucapião legal services) Listed by N0n Ransomware Group

Reported September 18, 2026.

HIGH
Severity
September 18, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Konnatus, a Brazilian usucapião legal-services firm, was listed on 18 September 2026 by the N0n ransomware group, which claims to have obtained data from the organisation. An undisclosed number of individuals may be affected; anyone who has shared personal information with Konnatus should verify their status with the company and review account security.

Severity & verification
HIGH severityUnverified claim
Account credentials exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware crews continue to pressure organisations by posting alleged victims on leak sites and threatening to release material if a settlement is not reached. Those listings are public accusations, not independent verification, and they often appear before any company statement or regulatory notice.

On 18 September 2026, the group known as N0n listed Konnatus, a Brazilian provider of usucapião legal services, on its leak site. As of writing, Konnatus has not publicly confirmed the claim. The number of people who might be affected is unknown, and the listing does not amount to proof that systems were compromised or that any files left the organisation.

What is being claimed

According to the N0n listing, Konnatus is associated with legal services and real estate activity in Brazil. The group claims that, if no settlement is reached by its deadline, it will publish material described as the application database—specifically chart of accounts, income and outflow structures, and account types—along with user accounts that include password hashes. Publication, the listing states, would proceed after that deadline.

Timing of any alleged intrusion, the method of access, the scale of any copy, and independent confirmation of the files are all undisclosed in the available record. People affected are listed as unknown. The description of what “will be published” is the group’s own marketing language on the leak site, not an audited inventory. Nothing in the public facts establishes that the claimed material was actually taken or that the threat will be carried out.

Who is N0n?

N0n is known publicly as a ransomware and extortion actor that operates in the familiar double-extortion pattern: encrypt or disrupt systems where it can, exfiltrate data where it claims to have done so, and use a leak site to name organisations and pressure payment. Groups in this category typically post short victim entries, set countdown-style deadlines, and threaten staged releases of alleged data dumps.

Public reporting on such crews generally notes opportunistic targeting across sectors rather than a single industry focus, use of standard ransomware playbooks, and reliance on fear of reputational and regulatory fallout. For this specific listing, only what appears on the leak site should be treated as the group’s claim. No additional statements by N0n about Konnatus beyond that listing are provided in the facts, and the listing itself remains unverified.

About Konnatus (usucapião legal services)

Konnatus is identified in the record as offering usucapião legal services—work tied to adverse-possession and related property regularisation under Brazilian law—within a broader legal-services and real-estate context. Firms in this niche typically help clients document long-term possession, assemble evidence for court or registry processes, and manage case files that sit at the intersection of identity, property, and financial documentation.

A leak-site claim against such a provider matters because the sector often handles sensitive personal and property-related records, client communications, and internal financial administration. A listing does not prove a breach occurred; it does mean clients, counterparties, and the public may see the organisation’s name tied to an extortion narrative until the company, a regulator, or another authoritative source addresses it. That reputational and uncertainty cost is real even when the underlying accusation is unconfirmed.

What data was at risk

The facts do not disclose a confirmed set of exposed data types. They only record what N0n says it would publish if no settlement is reached: an application database framed as chart of accounts, income and outflow structures, and account types, plus user accounts with password hashes. Those items should be read as the attacker’s claimed package, not as verified contents of a stolen archive.

If files of the kind legal and property-services firms commonly hold were ever involved, organisations in this sector typically maintain client identity and contact details, case and property documentation, billing and payment records, internal accounting structures, and staff or portal login data. Password hashes, if genuine and weakly protected, can enable offline cracking attempts; financial chart-of-accounts style data can reveal how money moves inside a practice. None of that inventory is established for this incident. Exact contents remain unconfirmed, and the count of affected individuals is unknown.

The real-world impact

For people who have dealt with a usucapião or related legal-services provider, the practical risk is conditional. If internal financial structures and user credentials were copied and later released, possible outcomes include targeted phishing that references real account or case language, attempts to reuse cracked passwords on other sites, and misuse of any personal details that might sit alongside business records. Property and legal matters can attract fraudsters who invent urgency around registries, fees, or “regularisation” payments.

For the organisation, an unverified leak-site listing can still drive client concern, support burden, and scrutiny from partners or authorities, regardless of whether a compromise is later confirmed. Extortion groups design that pressure deliberately. What the listing does establish is only that N0n chose to name Konnatus and to describe a threatened publication set. What it does not establish is theft, the accuracy of the file description, negligence, or the final fate of any data.

If your data was involved

Treat involvement as possible, not proven. If you are a client, vendor, or staff member who used Konnatus systems, sensible first steps focus on reducing reuse and social-engineering risk rather than assuming your records are already public.

Public detail on this listing remains limited. Until Konnatus or an official source confirms otherwise, the responsible stance is cautious hygiene and scepticism toward both the extortion narrative and anyone offering paid “fix” services off the back of it.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyKonnatus (usucapião legal services) security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Konnatus (usucapião legal services)’s full breach history →

More recent breaches

PayPal support operations (Transcom WorldWide) Listed by N0n Ransomware GroupSeptember 18, 2026AstraZeneca Türkiye Listed by N0n Ransomware GroupSeptember 18, 2026United Federation of Teachers Listed by N0n Ransomware GroupSeptember 18, 2026Argentem Creek Partners (investment firm) Listed by N0n Ransomware GroupSeptember 18, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Konnatus (usucapião legal services) Listed by N0n Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by n0n — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram