TOTVS
bd_8dccf695aea665bb · schema v1 · pii pii-v1
Full breach record for TOTVS →2 incidents on filePress / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage and machine-translated to English — verify against the source.
Summary
machine-translatedTOTVS faces cyber incident - Security Leaders. TOTVS: The Brazilian technology company TOTVS was the victim of a cyberattack, which was claimed by the BlackByte group, which stated it had stolen data from the company. TOTVS informed its clients of the incident and took measures to ensure the continuity of its services and operations. The company has not confirmed the extent of the attack or whether its clients were affected. Linked ransomware group: blackbyte.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Sep 30, 2024
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteblackbytebd_305040c6461fc41b2024-09-30Candidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
blackbyte
According to ransomware.live, Ransomware. Uses dropper written in JavaScript to deploy a .NET payload.