Ransomware victim disclosure
← All victimsFIEPE – Federação das Indústrias do Estado de Pernambuco
listed as fiepe.org.br · Claimed by Lockbit5 · listed 3 months ago
Status timeline
- ListedMar 30, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileFIEPE (Federação das Indústrias do Estado de Pernambuco) is the federation of industries for the state of Pernambuco, Brazil. It provides services to member trade unions and businesses of all sizes and sectors, including legal and administrative support, economic research, international trade facilitation via CIN-PE, issuance of industrial certificates and certificates of origin, and workforce training. It functions as a representative and support body for the industrial sector in Pernambuco.
- Industry
- Industrial Federation & Business Services
- Address
- Casa da Indústria, Recife, Pernambuco, Brazil
Attack summary
Severity: high — Data has been published (disclosed status: data_published) by a known ransomware group. FIEPE handles sensitive business, legal, and trade documents for a large number of industrial member companies across Pernambuco; exfiltration of this data could expose proprietary business information, member PII, and confidential union/legal records at significant scale. A data security notice was also posted on their site on 28.04.26, corroborating the incident.LockBit 5 claims to have attacked FIEPE and the disclosure status is listed as data_published, indicating that exfiltrated data has been released. The group describes FIEPE as an industrial organization that helps local businesses grow and succeed.
Data the group says was taken
AI dossier — extracted from the leak post- Business and industrial member records
- Economic research data
- Trade union administrative documents
- Certificates and legal documents
- Contact and organizational data
- Potentially employee and HR records
What the group claims
Fiepe is an industrial organization that helps local businesses grow and succeed. They work directly...
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

