LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › The PNST Listed by sarcoma Ransomware Group

HIGH severityUnverified claimHow we verify

The PNST Listed by sarcoma Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 26, 2025
The PNST Listed by sarcoma Ransomware Group

Reported March 26, 2025.

HIGH
Severity
March 26, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The PNST was listed by the sarcoma Ransomware Group on March 26, 2025, after internal files were exfiltrated in a ransomware attack. Anyone connected to the organisation should review the disclosure and take steps to protect their information.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

When a law firm appears on a ransomware group's leak site, the practical stakes fall first on clients, partners and staff whose private legal matters, contracts and personal details may have been copied. For anyone who has worked with The PNST, the listing raises immediate questions about whether confidential correspondence, identity documents or financial records are now outside the firm's control.

Public reporting on 26 March 2025 stated that the Brazilian firm Pacheco Neto Sanden Teisseire Advogados, known as The PNST, had been listed by the sarcoma ransomware group. The group claims internal files were exfiltrated. The number of people affected remains unknown, and further technical detail has not been released.

What happened

According to the available record, The PNST was listed by the sarcoma ransomware group on or around 26 March 2025. The listing describes a ransomware attack in which internal files were allegedly exfiltrated. No public confirmation of the precise date of intrusion, the method of initial access, the volume of data taken, or any ransom demand has been provided. The number of individuals whose information may be involved is listed as unknown. Beyond the group's claim that internal files were removed, the incident details remain limited.

The group behind it: sarcoma

Sarcoma is a ransomware operation that has appeared in public threat reporting as a group that encrypts systems and simultaneously steals data, then threatens to publish the material on a dedicated leak site if its demands are not met. Like other groups that follow this double-extortion model, sarcoma typically posts victim names and sample files to pressure organisations into payment. The listing of The PNST is therefore a claim made by the group itself; independent verification of the full contents or the success of any encryption has not been supplied in the public record. Prior activity attributed to sarcoma has followed the same pattern of data theft followed by public naming of victims, though specifics of those earlier cases are separate from the present listing.

About The PNST

The PNST is the trading name of Pacheco Neto Sanden Teisseire Advogados, a full-service Brazilian law firm formed by the merger of six partners and their teams. The firm describes itself as having both national and international focus, serving domestic clients and foreign investors, with particular experience in cross-border work involving European jurisdictions such as Germany, France and Scandinavia. Its practice covers the main industries and commercial matters typical of a mid-to-large Brazilian firm with multicultural staff. Law firms of this type routinely hold client files, contracts, correspondence, identity documents, financial records and privileged legal advice. A breach claim against such an organisation therefore carries weight because the material is often sensitive by nature and subject to professional secrecy obligations under Brazilian law.

What data was at risk

The public facts state only that internal files were exfiltrated in a ransomware attack. No inventory of file types, no count of records, and no confirmation of whether client personal data, employee information or privileged documents were among them has been released. Organisations of this kind typically store client identification details, contracts, litigation files, billing records and internal administrative documents. Because the exact contents remain undisclosed, it is not possible to state which specific categories were taken; the claim is limited to the removal of internal files.

The real-world impact

For individuals whose information may have been among the files, the concrete risks include potential misuse of personal identifiers, exposure of private legal or commercial matters, and the possibility of targeted phishing or social-engineering attempts that reference genuine case details. Clients involved in cross-border transactions or sensitive disputes may face particular concern if correspondence or strategy documents were copied. For the firm itself, the listing creates operational, reputational and regulatory consequences: the need to investigate the scope of any compromise, to notify affected parties where required by Brazilian data-protection rules, and to restore confidence among clients who entrust it with confidential work. Because the number of people affected is unknown and the precise data types unconfirmed, the full scale of these effects cannot yet be measured.

What to do if you're exposed

Anyone who has been a client, employee or counterpart of The PNST should treat the listing as a prompt to review their own exposure. Monitor bank and credit accounts for unusual activity, enable multi-factor authentication on email and financial services, and be alert to unexpected messages that appear to reference legal or commercial matters connected to the firm. If you receive notices from the firm itself, follow the instructions they provide for further steps. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Keep records of any suspicious contact and consider placing fraud alerts with relevant credit agencies if identity documents may have been involved. Public detail on this incident remains limited, so continued monitoring of official statements from the firm is advisable.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyThe PNST security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See The PNST’s full breach history →

More recent breaches

MACMA Werbeartikel oHG Listed by sarcoma Ransomware GroupSeptember 25, 2025Miami Management Listed by sarcoma Ransomware GroupSeptember 22, 2025Kwg Listed by sarcoma Ransomware GroupSeptember 17, 2025Milberg Listed by sarcoma Ransomware GroupJuly 8, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the The PNST Listed by sarcoma Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by sarcoma — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram