LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › PontoBR Sistemas Listed by spacebears Ransomware Group

HIGH severityUnverified claimHow we verify

PontoBR Sistemas Listed by spacebears Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 5, 2026
PontoBR Sistemas Listed by spacebears Ransomware Group

Reported August 5, 2026.

HIGH
Severity
1
Data types exposed
August 5, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

PontoBR Sistemas was listed by the spacebears ransomware group on August 05, 2026, after internal files were exfiltrated in a ransomware attack. Because the number of people affected remains undisclosed, anyone who has shared data with PontoBR Sistemas should verify their status and consider protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the PontoBR Sistemas Listed by spacebears Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account. Details go to your inbox.

People whose information may sit inside PontoBR Sistemas systems now face a concrete uncertainty: a ransomware group has publicly listed the company and claims to have taken internal files. When an IT provider that supports call-center platforms and public-examination systems appears on a leak site, the practical risk is that work records, contact details, or operational data tied to employees, clients, or exam candidates could surface or be misused. Public detail on exactly who is affected remains limited.

On 5 August 2026 the organisation PontoBR Sistemas was reported as listed by the group known as spacebears. The listing asserts that internal files were exfiltrated in a ransomware attack. The number of people affected is unknown, and no fuller inventory of the taken data has been published in the available record.

Inside the incident

According to the reported information, PontoBR Sistemas was listed by the spacebears ransomware group on or around 5 August 2026. The group’s claim is that internal files were exfiltrated during a ransomware attack. No public confirmation of the attack’s technical method, the precise date of intrusion, the volume of data, or any ransom demand appears in the available facts. The number of individuals whose information may be involved is stated as unknown. Beyond the group’s listing and the description of “internal files,” further operational detail has not been disclosed.

Because the record rests on a leak-site claim rather than an independently verified disclosure from the company, the scope and confirmation of the incident remain limited to what has been reported. No statement from PontoBR Sistemas itself is included in the facts provided.

Who is spacebears?

spacebears is a ransomware actor known in public reporting for double-extortion operations: encrypting victim systems while also copying data and threatening to publish it if payment is not made. Groups operating in this style commonly maintain dedicated leak sites where they post victim names, sample files, or full archives to increase pressure. Their listings are claims until corroborated by the victim or by independent forensic evidence.

In this case, spacebears has listed PontoBR Sistemas and asserts that internal files were taken. No additional statements attributed to the group about this specific victim—such as file counts, screenshots, or deadlines—are present in the given facts. Readers should treat the listing as an unverified claim by the threat actor rather than as confirmed fact.

PontoBR Sistemas and its sector

PontoBR Sistemas is described as an IT firm founded in 2008 in Brazil. It specialises in advanced call-center technologies, including its proprietary Discador Tabulare, and also provides public-examination management systems. The company supplies tailored software solutions and IT infrastructure services and has received recognition from the Brazilian federal innovation agency FINEP.

Organisations in this sector typically sit between businesses, contact-center operators, and public or semi-public examination bodies. They often hold configuration data, call-routing logic, user accounts for platform administrators, and records related to exam scheduling or candidate management. A breach at such a provider can therefore touch both commercial clients and individuals who interact with those clients’ services. The consequential nature of an incident here stems from that intermediary role: data that belongs to multiple parties may reside on the same systems.

What was likely exposed

The available facts name the exposed material only as “internal files exfiltrated in ransomware attack.” No further breakdown—customer lists, employee records, examination data, source code, or credentials—is supplied. Exact contents therefore remain unconfirmed.

Organisations of this type commonly hold categories of information that, if taken, would raise concern. In general terms those categories can include:

None of the above should be read as a confirmed inventory for this incident. Public detail is limited to the phrase “internal files,” and any assumption beyond that would be speculation.

Why it matters

For individuals, the real-world risk is that personal or professional information held by PontoBR Sistemas or its clients could be published, sold, or used in follow-on fraud. Call-center and examination-related data can contain names, contact details, identification numbers, or scheduling information that enable phishing, impersonation, or targeted social engineering. Because the number of people affected is unknown, anyone who has interacted with the company’s platforms or with organisations that use them has reason to remain alert rather than assume they are untouched.

For the organisation itself, a ransomware listing can disrupt operations, damage client trust, and trigger contractual or regulatory obligations under Brazilian data-protection rules. Even when encryption is reversed or systems are restored, the separate problem of exfiltrated files can persist for months if the data later appears on criminal forums. The absence of a confirmed victim count or data inventory simply prolongs that uncertainty for everyone involved.

If your data was in this breach

If you believe you may be connected to PontoBR Sistemas—as an employee, client contact, exam candidate, or user of a service that relies on its software—practical first steps are straightforward. Monitor financial and email accounts for unexpected activity. Treat unsolicited messages that reference call-center platforms, examinations, or Brazilian IT services with caution. Change passwords on any accounts that shared credentials or email addresses with systems the company might have supported, and enable multi-factor authentication where it is available. Consider placing fraud alerts with relevant credit or identity services if you have reason to think identity documents were stored.

You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm or deny involvement in this specific incident, but it can show whether the same address has appeared elsewhere and help you prioritise further monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPontoBR Sistemas security record
64/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See PontoBR Sistemas’s full breach history →

More recent breaches

StellarRAD Systems Listed by spacebears Ransomware GroupJuly 29, 2026DoAllTech Listed by spacebears Ransomware GroupJuly 21, 2026Turbosoft Listed by spacebears Ransomware GroupJuly 13, 2026Techpol-System Listed by spacebears Ransomware GroupJuly 13, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the PontoBR Sistemas Listed by spacebears Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by spacebears — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram