DisclosureLens
GLOBALMalwareEnergy & UtilitiesUtilitiesRansomwareRansomhouseRansom DemandedActor NamedData Leak ThreatenedData PublishedHigh

Sabesp

bd_8f0fb5d0f04fef8b · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Oct 17, 2024

To disclose

Affected

Not disclosed

Confidence

50%
Full breach record for Sabesp

Threat-actor claim — not a regulatory filing

This row is a claim by the ransomware group Ransomhouse on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Group activity: EnergyDiscovered: 2024-11-01

Source: Ransomware.live

Post text · scraped from the leak site

In the name of our partners we apologize for the inconveniences that many people have to bear because of the incident. But we also want to explain the situation a bit more.First of all, the stories the Sabesp representatives tell you that they will restore their infrastructure are all lies.Our partners report that more than 2.000 servers were taken down and there are no chances those will be restored without our help as the company has no backups. If they had that data backed up, that would have already been restored.Taking into account the level of professionalism of the IT crew employeed in the company and the third parties the company has contracts with, restoration would take a minimum of 6 months or perhaps even more.With regard to company claims that no personal data was leaked, that's also not true. That was simply not disclosed yet.In addition to that, the company contacted us in the first days and we offered our help to solve the problem once and for all, but they've decided their money is more important than their clients and simple folk. At the same time we've received information they are taking a lot of cash out of the company for the purposes hardly related to solving the problem for people if you know what we mean.With our help the company infrastucture could be restored in 4-6 hours and everything could get back to normal the same day.The steps the company takes indicate that its management has no value for people and clients, the only things they have value for is money and profit, unfortunately.

Incident timeline — mostly unverified

? — ?

Breach window unknown

Oct 17, 2024

Claim posted

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Claim → filing

Compliance clock

Not assessable

Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident

Evidence ladder

Leak-site claimThis record

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.

Source ceiling

  • actor name
  • victim claim
  • ransom/leak status
  • discovery date
  • materiality
  • notification
  • affected count
  • confirmed data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2021-06-01

ransomhouse

According to ransomware.live, RansomHouse is a double-extortion RaaS operation active since late 2021, attributed to the threat actor "Jolly Scorpius," targeting over 120 organizations across healthcare, finance, transportation, and government, recently upgrading to a multi-layered dual-key encryption architecture.

212 tracked hereFull profile →