selmi.com.br Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The selmi.com.br Listed by lockbit3 Ransomware Group (reported July 11, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On July 11, 2023, the Brazilian food manufacturer selmi.com.br was listed by the ransomware group known as lockbit3. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed.
The listing itself is a claim published by the group. For employees, partners, and others who may have had dealings with the company, the incident raises ordinary questions about what information left its systems and what practical steps follow when a ransomware group asserts it holds internal material.
What happened
According to the available record, selmi.com.br appeared on a lockbit3 leak site on or around July 11, 2023. The reported summary describes the event as a ransomware attack in which internal files were allegedly exfiltrated. No confirmed figure for the volume of data, no technical description of the initial access method, and no independent verification of the group’s claims have been supplied in the public facts. The number of individuals whose information may be involved is listed as unknown. Beyond the assertion that internal files were taken, the precise scope and contents of any stolen material remain undisclosed.
Who is lockbit3?
LockBit3 is a well-documented ransomware operation that has appeared repeatedly in public reporting since earlier iterations of the LockBit brand. Groups operating under this name typically gain access to an organization’s network, move laterally, exfiltrate data, and then encrypt systems while threatening to publish or auction the stolen material if a ransom is not paid. They maintain leak sites on which they list victims and, in some cases, release sample files or larger archives. Their activity has spanned multiple sectors and countries. In this instance, the appearance of selmi.com.br on such a listing constitutes a claim by the group; it does not by itself confirm the full extent of any intrusion or the authenticity of every file the group may later display. No statements attributed specifically to lockbit3 about this victim, beyond the fact of the listing and the description of internal-file exfiltration, are contained in the provided facts.
selmi.com.br and its sector
Selmi.com.br is a Brazilian manufacturer of flour-based products. Public background supplied with the incident record states that the company was established in 1966 and produces dry pasta, traditional pasta, cookies, crackers, cakes, and baking mixes. It employs more than 1,000 people, operates two production sites, and maintains thirteen distribution centers across the country. Organizations of this kind sit in the food-manufacturing and consumer-goods supply chain. They routinely hold employee records, supplier and distributor contracts, production and logistics data, quality and regulatory documentation, and commercial information tied to retailers and business customers. A ransomware incident affecting such a firm can therefore touch both internal workforce data and information belonging to commercial partners, even when the exact inventory of stolen files is not yet public.
The information in question
The facts name the exposed material only as “internal files exfiltrated in a ransomware attack.” No further breakdown—such as whether the files included human-resources databases, customer or supplier lists, financial records, or operational documents—has been provided. Because the precise contents remain unconfirmed, it is not possible to state as fact which categories of personal or commercial data were taken. Companies in food manufacturing commonly retain payroll and personnel files, vendor agreements, shipment and inventory data, and internal correspondence. Any of those categories could theoretically be present among “internal files,” yet that remains an inference from sector norms rather than a verified inventory of this incident. Readers should treat specific data-type claims as unconfirmed until corroborated by the company or by independent analysis of released material.
Why it matters
When internal files leave an organization through a ransomware intrusion, the practical risks are concrete even if the exact file list is unknown. Employees may face exposure of contact details, identification numbers, or compensation information that can be misused for phishing or identity fraud. Suppliers and distributors may find commercial terms, pricing, or logistics data circulating in ways that affect negotiations or competitive position. The organization itself must contend with operational disruption, potential regulatory notification duties under applicable Brazilian and sector rules, and the longer task of verifying what was taken and notifying those affected. Because the number of people impacted is listed as unknown, the circle of individuals who should remain alert is correspondingly broad: current and former staff, contractors, and business partners who exchanged documents with the firm. None of these consequences require assuming negligence; they follow from the ordinary reality that internal corporate repositories contain information others can exploit once it is copied off-network.
If your data was in this claimed breach
If you have a past or present relationship with selmi.com.br—as an employee, contractor, supplier, or distributor—treat the possibility of exposure seriously until more detail emerges. Monitor financial and email accounts for unexpected messages that reference the company or request urgent action. Enable multi-factor authentication where it is available, and be cautious of unsolicited attachments or links. Consider placing fraud alerts with relevant credit or identity-protection services if you believe sensitive personal identifiers may have been involved. You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. Keep records of any suspicious contact, and follow official notices from the company should they publish confirmation or guidance. Public information about this incident remains limited; further clarity will depend on additional statements or verified analysis of any material the group releases.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ibp.com.br Listed by lockbit3 Ransomware Groupgelco-s-a.com.br Listed by lockbit3 Ransomware Groupcopral.com.br Listed by lockbit3 Ransomware Groupontariopork.on.ca Listed by dispossessor Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the selmi.com.br Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.