Ransomware victim disclosure
← All victimsSIAPE / SIAPEnet - Brazilian Federal Government Payroll System
listed as siapenet.gov.br · Claimed by apt73 · listed 24 days ago
Status timeline
- Listed
Apr 27, 2026
- Data leaked
At a glance
- Group
- apt73
- Status
- Data leaked
- Country
- BR
- Sector
- Public Sector
- Listed on leak site
- Apr 27, 2026
About the victim
AI dossier — public-source company profileSIAPEnet (Sistema Integrado de Administração de Pessoal) is the Brazilian federal government's integrated personnel and payroll administration system, operated under the Ministry of Management and Innovation in Public Services (MGI). It processes the remuneration of federal civil servants across all branches of the Brazilian federal administration. The portal serves as the web interface through which civil servants and retirees access payroll, benefit, and personnel data.
- Industry
- Federal Government Human Resources & Payroll Administration
- Address
- Brasília, Distrito Federal, Brazil
Attack summary
Severity: critical — SIAPEnet is a core Brazilian federal government payroll system processing PII and financial remuneration data for potentially hundreds of thousands of federal civil servants; confirmed exfiltration and publication of such data from a government system constitutes a critical breach of regulated, sensitive PII at scale in the public sector.The group APT73 claims to have compromised SIAPEnet and exfiltrated data related to the remuneration and personal records of Brazilian federal civil servants; the status is listed as data_published, indicating the group asserts they have already released stolen data.
Data the group says was taken
AI dossier — extracted from the leak post- Federal civil servant remuneration records
- Personnel administration data
- Government payroll data
- Civil servant personal identifying information
What the group claims
Today, SIAPE processes the remuneration of civil servants, regulated both by the uniform federal ...
Sources
Source
Indexed 24 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
