Ransomware victim disclosure
← All victimsWS Soluções Corporativas Ltda
listed as ws.com.br · Claimed by Threeam · listed 20 hours ago
Status timeline
- ListedJun 12, 2026
- Data leakeddate unknown
At a glance
- Group
- Threeam
- Status
- Data leaked
- Country
- Brazil
- Sector
- Business Services
- Listed on leak site
- Jun 12, 2026
About the victim
AI dossier — public-source company profileWS Soluções Corporativas Ltda is a Brazilian labor staffing and business services provider founded in 1991. Operating primarily in Bahia, Sergipe, and Espírito Santo states, the company provides administrative and operational workforce placement, facility cleaning, technical maintenance, hospital hygienization, and recruitment services to government, institutional, and commercial clients.
- Industry
- Labor & Business Services Staffing
- Address
- Edf. Salvador Shopping Business, Torre Europa, nº 1057, Sala 1808, Salvador – Bahia, Brazil
- Founded
- 1991
Attack summary
Severity: medium — Data has been published by the group. The company handles employee and client PII at scale (administrative/staffing operations), but no specific sensitive regulated data (medical, financial records) is confirmed exfiltrated. Moderate scale exposure of business and personnel data.The threat actor 'threeam' claims to have compromised WS Soluções Corporativas Ltda and exfiltrated data. The group disclosed the attack with data_published status, though specific data types and operational impact are not detailed in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Employee records
- Client information
- Administrative and financial data
- Personnel files
What the group claims
WS Group Brasil is a Brazilian operations and business services provider engaged in logistics, technical support, contract administration, and labor-intensive service delivery. The company serves a mix of government, institutional, and commercial
Sources
Source
Indexed 20 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

