Petrobras / SAExploration Listed by everest Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Petrobras and SAExploration were listed by the Everest ransomware group on November 17, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may be affected; check the organizations’ notices and change any exposed credentials immediately.
Inside the incident
The only confirmed detail is the listing itself. The group asserts that files were taken from the target, yet no independent verification of the claim, no file counts, and no descriptions of the data have been released. The date of the intrusion, the entry point used by the attackers, and whether encryption was also deployed are not stated in available records.
Inside everest
Everest is a ransomware operation that follows the double-extortion model common among current groups: data is copied before encryption, and the threat actors then publish samples or file listings on a dedicated leak site to pressure victims. The group has previously posted claims against organisations in energy, manufacturing, and professional services. Its listings constitute an assertion by the actors rather than a claimed breach until corroborated by the victim or investigators.
About Petrobras / SAExploration Listed by everest Ransomware Group
Petrobras is a state-owned Brazilian company engaged in oil and gas exploration, production, refining, and distribution. SAExploration is a U.S.-based provider of seismic data acquisition services, including deep-water ocean-bottom and land-based surveys for the energy sector. Both organisations routinely handle technical, operational, and commercial records that support exploration projects and infrastructure decisions.
What data was at risk
The listing refers only to “internal files.” No inventory of document types, databases, or personal information has been published. Organisations in this sector commonly maintain seismic survey data, well logs, contractual agreements, employee records, and vendor communications; however, whether any of these categories were actually taken in this case is unconfirmed.
What's at stake
Exposure of operational files could reveal proprietary exploration methods or commercial terms, while any personal data present could be used for targeted fraud or further social-engineering attempts. For the companies, the immediate consequences are the cost of investigation, potential regulatory scrutiny in Brazil and the United States, and the need to review access controls across joint or contractor environments.
If your data was in this claimed breach
Monitor official statements from Petrobras and SAExploration for any confirmation or guidance. Enable multi-factor authentication on accounts that may share credentials with the affected organisations, and review recent login activity. Individuals can run a free exposure scan of their email address against known breach data to check whether their information has appeared in previously published datasets.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Petrobras Campos Basin 3D & 4D Seismic Survey Data Listed by everest Ransomware GroupChrysler Listed by everest Ransomware GroupSarmap Listed by everest Ransomware GroupVikor Scientific, LLC / Korgene Listed by everest Ransomware GroupLatest breaches
Publicly posted by everest — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.