LockBit lists Brazilian firm rai.com.br
Ransomware.live's leak-site tracker shows LockBit added Brazilian company rai.com.br as a new victim, with limited technical detail disclosed.
The entry, indexed by Ransomware.live, documents a new victim listing attributed to the LockBit ransomware operation for the domain rai.com.br. The posting includes only aggregate figures sourced from third-party infostealer telemetry (Hudson Rock) — reporting 4 compromised employees, 163 compromised users, 12 third-party employee credentials, and 25 external attack-surface findings — rather than details of the intrusion method, data exfiltrated, or ransom demand.
No stolen data, file listings, or technical indicators of compromise beyond the victim's domain are disclosed in this listing; the platform explicitly does not host or redistribute leaked content. As with most leak-site postings, this represents disclosure of a claimed victim by a known ransomware brand rather than a novel technique or newly observed campaign, and the entry should be treated as a routine addition to LockBit's victim list pending further corroboration or additional leaked data.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/cmFpLmNvbS5ickBsb2NrYml0NQ==
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free