# LockBit lists Brazilian firm rai.com.br

Published: 2026-08-03 · Severity: medium
Canonical: https://vorant.io/reports/d597be1c-0f63-56bc-bb8b-7fb9dea02f52/lockbit-lists-brazilian-firm-rai-com-br

> Ransomware.live's leak-site tracker shows LockBit added Brazilian company rai.com.br as a new victim, with limited technical detail disclosed.

The entry, indexed by Ransomware.live, documents a new victim listing attributed to the LockBit ransomware operation for the domain rai.com.br. The posting includes only aggregate figures sourced from third-party infostealer telemetry (Hudson Rock) — reporting 4 compromised employees, 163 compromised users, 12 third-party employee credentials, and 25 external attack-surface findings — rather than details of the intrusion method, data exfiltrated, or ransom demand.

No stolen data, file listings, or technical indicators of compromise beyond the victim's domain are disclosed in this listing; the platform explicitly does not host or redistribute leaked content. As with most leak-site postings, this represents disclosure of a claimed victim by a known ransomware brand rather than a novel technique or newly observed campaign, and the entry should be treated as a routine addition to LockBit's victim list pending further corroboration or additional leaked data.

## Mentioned in this report

- Threat actors: LockBit
- Malware: LockBit

Source reporting: https://www.ransomware.live/id/cmFpLmNvbS5ickBsb2NrYml0NQ==

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d597be1c-0f63-56bc-bb8b-7fb9dea02f52/lockbit-lists-brazilian-firm-rai-com-br.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
