Prefeitura Municipal de Saquarema Listed by avaddon Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Prefeitura Municipal de Saquarema Listed by avaddon Ransomware Group (reported September 9, 2021) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On September 9, 2021, the Prefeitura Municipal de Saquarema appeared on a leak site associated with the Avaddon ransomware group. The group claims to have exfiltrated internal files from the municipal government during a ransomware attack.
Public reporting on the incident provides no confirmed figures for the volume of data involved, the number of individuals affected, or the timeline of the underlying intrusion. The listing itself constitutes the primary public indication that material was taken.
Breaking down the breach
The only confirmed public detail is the appearance of the municipality on the Avaddon leak site on the reported date. The group states that internal files were removed, but no further technical description of the access method, encryption deployment, or data volume has been released by either the actor or the organization.
Because the municipality has not issued a detailed statement on the event, the duration of any unauthorized access and the scope of systems reached remain unknown. No ransom demand amount or payment status has been disclosed in available records.
Who is avaddon?
Avaddon operated as a ransomware-as-a-service group that relied on double-extortion tactics. After encrypting systems, the operators would threaten to publish stolen files on a dedicated leak site unless payment was received. The group was publicly active from roughly 2020 through late 2021 and targeted organizations across multiple countries and sectors.
Its listings were presented as evidence of successful data theft, yet independent verification of the claimed material was rarely possible from outside observers. The group ceased visible operations after law-enforcement actions against its infrastructure and affiliates.
Who is Prefeitura Municipal de Saquarema?
The Prefeitura Municipal de Saquarema is the local executive authority for the municipality of Saquarema in Rio de Janeiro state, Brazil. Like other Brazilian municipal governments, it administers public services including civil registry functions, tax collection, health and education records, and procurement.
Entities of this type routinely process identifying information of residents, employees, and vendors. A compromise therefore carries the potential to expose data held on behalf of the local population rather than only internal administrative material.
What was likely exposed
The facts released to date name only “internal files exfiltrated in ransomware attack.” No inventory of file types, databases, or record categories has been published.
Municipal governments commonly maintain citizen identification records, tax and property data, payroll information, and limited health or education documentation. Whether any of these categories were among the claimed files cannot be confirmed from the information currently available.
The real-world impact
Residents whose records are held by the municipality face the standard risks associated with exposure of government-held personal data: potential misuse for identity-related fraud or targeted scams. The absence of confirmed data categories makes it impossible to assess the scale of that risk for any individual.
For the organization, the incident adds to the operational burden of incident response, possible regulatory notifications under Brazilian data-protection rules, and the need to review access controls and backup integrity. No public information indicates whether systems were restored or whether services were interrupted.
What to do if you're exposed
Individuals concerned about possible exposure should monitor official communications from the Prefeitura Municipal de Saquarema for any guidance on affected records. Basic protective steps include reviewing bank and credit statements for unusual activity and enabling multi-factor authentication on accounts that use the same email address held by the municipality.
Readers may also run a free exposure scan of their email address against known breach data sets to determine whether their information has appeared in previously published incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
COMUNE DI VILLAFRANCA D'ASTI Listed by avaddon Ransomware GroupMUNICIPIO DE QUATRO BARRAS Listed by avaddon Ransomware GroupOLOMOUC Listed by avaddon Ransomware GroupPartit Nazzjonalista Listed by avaddon Ransomware GroupLatest breaches
Publicly posted by avaddon — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.