Home All Victims Sabesp

Sabesp

ransomhouse

This record tracks a ransomware attack claimed by the ransomhouse group against Sabesp. It collects the publicly disclosed attack details — sector, location and timeline — as published on the operator's leak site and indexed by Breach House.

Window Zero

EXPOSURE GAP

Window Zero is the time the breach stayed in the open before anyone said so — the gap between when the attack was first discovered on the operator's leak site (t1) and when it was publicly disclosed (t2). The wider this window, the longer victims, staff and customers were exposed with no warning.

685days open
t1 · Published t2 · Pending
Oct 17, 2024Not disclosed yet
Country
Business Category
Communication / Marketing
Employees
51-100
Discovered
2024-11-01
Published
October 17, 2024
Disclosed / Notified
Not disclosed yet
Victim ID
egM6V9pb3UJS

Attack Summary

In the name of our partners we apologize for the inconveniences that many people have to bear because of the incident. But we also want to explain the situation a bit more.First of all, the stories the Sabesp representatives tell you that they will restore their infrastructure are all lies.Our partners report that more than 2.000 servers were taken down and there are no chances those will be restored without our help as the company has no backups. If they had that data backed up, that would have already been restored.Taking into account the level of professionalism of the IT crew employeed in the company and the third parties the company has contracts with, restoration would take a minimum of 6 months or perhaps even more.With regard to company claims that no personal data was leaked, that's also not true. That was simply not disclosed yet.In addition to that, the company contacted us in the first days and we offered our help to solve the problem once and for all, but they've decided their money is more important than their clients and simple folk. At the same time we've received information they are taking a lot of cash out of the company for the purposes hardly related to solving the problem for people if you know what we mean.With our help the company infrastucture could be restored in 4-6 hours and everything could get back to normal the same day.The steps the company takes indicate that its management has no value for people and clients, the only things they have value for is money and profit, unfortunately.

Leak Screenshots

SAMPLE

This is what a leak gallery looks like. Sign in to see the screenshots our collector has actually taken of this listing.

file_tree.png
finance_2024.xlsx
passport_scan.jpg
contract_signed.pdf
Sign in or explore HaveIBeenRansom to view the full leak gallery.
View leak gallery →

Dark Web Exposure

Findings for sabesp.com.br — indexed by HaveIBeenRansom.
25,407
found in Infostealer logs
2,979+
found in Traditional breaches
21+
found in Ransomware leaks
Capesesp
akira · breach
••• emails
Apollo.io DB 816millions.rar
Database World ROC · breach
••• emails
@BreachedData1 LinkedIn 2021-23 Cleaned.7z.001
Database World ROC · breach
••• emails
TAPAir_BF.7z
B F R e p o V 3 F i l e s · breach
••• emails
Cit0day [cit0day.in] breaches.csv
LKnet reserve chat · breach
••• emails
Database World ROC · breach
••• emails
formaceft_db · breach
••• emails
B F R e p o V 3 F i l e s · breach
••• emails
+ 17 more leak sources locked
Leak volumes are locked
Sign in to reveal how many records each source exposed and the remaining 20 sources.
Want the complete picture — passwords, machines, full leak files? It's all searchable on HaveIBeenRansom.
Search this victim →
Visit Website Original Post View Group: ransomhouse
Legal Disclaimer: This ransomware victim record reflects information published on the operator's leak site. Breach.house only records what the operators themselves publish in the open. We take screenshots of their public pages and keep the proof material they post there, so that a listing can be verified and its status tracked over time. We do not purchase data, we do not solicit or encourage its publication, we do not access any private system, and we do not alter anything we record. Nothing is offered for download here, and detailed content is not published on this page or anywhere else on the public site: access to it is restricted to vetted customers under contract, for incident response, due diligence and cyber-resilience work. Breach.house is not affiliated with, and does not act on behalf of, the operators who publish this material. If you represent an organisation or individual named here and want a record reviewed or removed, contact us and we will act on it.