Ransomware victim disclosure
← All victimsDX.On
listed as dxon.com.br · Claimed by 0day Syndicate · listed 3 days ago
Status timeline
- Listed
May 28, 2026
- Data leaked
At a glance
- Group
- 0day Syndicate
- Status
- Data leaked
- Country
- BR
- Sector
- Business Services
- Listed on leak site
- May 28, 2026
About the victim
AI dossier — public-source company profileDX.On is a Brazilian data intelligence and technology company headquartered in São Paulo that specializes in risk management, fraud prevention, and compliance solutions. Operating in B2B mode across insurance, credit, debt collection, and compliance sectors, the company processes over 40 billion data transactions annually and serves fintechs, banks, insurers, pension funds, utilities, and government entities.
- Industry
- Data Intelligence & Risk Management / Financial Services Technology
- Address
- Av. das Nações Unidas, 12399, 7º Andar - Brooklin Paulista, CEP 04578-000, São Paulo, SP, Brazil
Attack summary
Severity: high — DX.On processes sensitive financial and personal data at scale (40B+ annual transactions) for regulated sectors (insurance, credit, banking, compliance). Exfiltration of such data would expose PII and financial information of end-users across multiple institutions, with regulatory (LGPD) implications. However, no proof files or specific data inventory details are published in the post, preventing a 'critical' classification.0day Syndicate claims to have breached DX.On and exfiltrated data. The leak post provides no specific details on the scope of exfiltration, data types compromised, or operational impact.
Data the group says was taken
AI dossier — extracted from the leak post- customer data
- transactional records
- fraud prevention datasets
- compliance information
What the group claims
DXON is a Brazilian company that provides data intelligence and fraud prevention solutions.
Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
