Ransomware victim disclosure
← All victimsSelpe Consultoria de RH
listed as gruposelpe.com.br · Claimed by LockBit · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- LockBit
- Status
- Data leaked
- Country
- Brazil
- Sector
- Business Services
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileSelpe Consultoria de RH is a Brazilian HR consulting firm with approximately 60 years of market experience, offering services across the full people management cycle including recruitment and selection, executive search, temporary staffing, trainee programmes, and HR advisory. The company operates multiple offices across Brazil (Belo Horizonte, São Paulo, Recife, Contagem, Conselheiro Lafaiete, Uberlândia) and is a member of NPA Worldwide, an international executive search network, as well as a partner of Interim Management Worldwide.
- Industry
- Human Resources Consulting & People Management
- Address
- Belo Horizonte, MG, Brazil (additional units in São Paulo/SP, Recife/PE, Contagem/MG, Conselheiro Lafaiete/MG, Uberlândia/MG)
Attack summary
Severity: high — Data has been published (not merely threatened), and an HR consultancy holds substantial volumes of PII — including candidate profiles, employee records, and client business data — across many organisations, representing significant third-party data exposure at scale.LockBit claims to have attacked Selpe Consultoria de RH and has published data (disclosed status: data_published), indicating exfiltration of company data. The specific data categories and volume exfiltrated were not detailed in the leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- HR and recruitment records
- Candidate personal data
- Client company information
- Employee data
- Business advisory documents
What the group claims
Selpe Consultoria de RH specializes in human resources and people management, offering services in r...
Sources
- Victim sitegruposelpe.com.br
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

