LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › www.sonoshowmoveis.com.br Listed by alphalocker Ransomware Group

HIGH severityUnverified claimHow we verify

www.sonoshowmoveis.com.br Listed by alphalocker Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 29, 2025
www.sonoshowmoveis.com.br Listed by alphalocker Ransomware Group

Reported September 29, 2025.

HIGH
Severity
September 29, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

www.sonoshowmoveis.com.br was listed by the alphalocker ransomware group on 29 September 2025, with internal files reportedly taken in the attack; the number of people affected is undisclosed and the date of the intrusion itself has not been established. Individuals should check whether their data was exposed and follow any official guidance on protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target mid-sized commercial organisations across many sectors, using data theft and public leak-site listings as leverage. In this environment, even companies that do not appear to be high-profile technology firms can find themselves named by threat actors seeking payment. On 29 September 2025, the Brazilian furniture retailer www.sonoshowmoveis.com.br was listed by the alphalocker ransomware group, which claims to have exfiltrated internal files during an attack.

Public detail remains limited. The number of people affected is unknown, and independent confirmation of the intrusion has not been published. What is known comes from the group’s own listing and a brief reported summary of the material it says it obtained. For customers, suppliers and staff connected to the company, the listing raises practical questions about what may have been taken and what steps are now prudent.

Inside the incident

According to the available record, www.sonoshowmoveis.com.br was listed by the alphalocker ransomware group on 29 September 2025. The group claims that internal files were exfiltrated as part of a ransomware attack. A reported summary describes approximately 23 GB of data that includes material related to clients, projects and financial documentation, among other items. No further technical details—such as the initial access method, the precise date of intrusion, or whether systems were encrypted—have been disclosed in the public facts. The number of individuals whose information may be involved is listed as unknown. The listing itself constitutes a claim by the group rather than an independently verified statement of compromise.

Who is alphalocker?

Alphalocker is a ransomware group that operates in the established double-extortion model common among contemporary ransomware actors. Groups of this type typically gain access to a victim’s network, exfiltrate data, and then threaten to publish or sell the material on a dedicated leak site if a ransom is not paid. Public reporting on alphalocker has described it as one of several actors that maintain such sites and post victim names together with sample data or volume claims to increase pressure. Like other ransomware operations, it has been observed targeting organisations of varying sizes rather than exclusively large enterprises. Specific claims made by the group about any individual victim, including the volume or content of data taken from www.sonoshowmoveis.com.br, should be treated as assertions by the actor until corroborated by the organisation or independent investigators.

Who is www.sonoshowmoveis.com.br?

www.sonoshowmoveis.com.br is the online presence of a Brazilian furniture retailer. Companies of this type typically manage customer orders, project or custom-furniture records, supplier relationships, and routine financial documentation. They may also hold contact details, delivery addresses and payment-related information for clients. A breach affecting such an organisation is consequential because the data it holds can be used for targeted fraud, social-engineering attempts against customers or partners, and competitive or financial harm to the business itself. Even when the precise scope of exposure remains unconfirmed, the mere public listing can erode trust and create operational disruption while the company investigates and responds.

The information in question

The facts state that internal files were exfiltrated and that the reported volume is 23 GB. The summary associated with the listing names clients, projects and financial documentation among the categories of material claimed to have been taken. Exact file inventories, the presence or absence of personal identifiers, and the full range of data types have not been independently confirmed. Organisations in the retail furniture sector commonly store customer contact and order information, project specifications, invoices, accounting records and internal correspondence. Whether any of those categories were in fact included in the claimed 23 GB set remains unverified beyond the group’s assertion. The number of people potentially affected is unknown.

The real-world impact

If the claimed data are authentic, individuals whose details appear in client or project files could face elevated risk of phishing, identity-related fraud or unwanted contact. Financial documentation, if genuine, might assist criminals in crafting more convincing scams or in identifying payment patterns. For the organisation, the listing can generate reputational damage, regulatory scrutiny under Brazilian data-protection rules, and the cost of forensic investigation, notification and remediation. Because the scale of affected individuals is undisclosed, the practical impact cannot yet be quantified; the primary immediate effect is uncertainty for anyone who has done business with the company.

What to do if you're exposed

Anyone who has been a customer, supplier or employee of www.sonoshowmoveis.com.br should treat the listing as a reason for caution rather than confirmed personal compromise. Monitor bank and credit-card statements for unexpected activity, be sceptical of unsolicited messages that reference furniture orders or payments, and consider changing passwords on accounts that reuse credentials shared with the company. If you receive communications claiming to come from the retailer, verify them through known official channels. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets; such a scan provides an additional, independent signal of exposure risk.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companywww.sonoshowmoveis.com.br security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See www.sonoshowmoveis.com.br’s full breach history →

More recent breaches

www.mercantetubos.com.br Listed by alphalocker Ransomware GroupOctober 13, 2025www.bew.co.th Listed by alphalocker Ransomware GroupNovember 16, 2025www.automotiveml.com Listed by alphalocker Ransomware GroupNovember 3, 2025www.unterkofler.info Listed by alphalocker Ransomware GroupNovember 3, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the www.sonoshowmoveis.com.br Listed by alphalocker Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by alphalocker — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram