Ransomware victim disclosure
← All victimsRodon (rodoviariaonline.com.br)
listed as rodoviariaonline.com.br · Claimed by Ransomedvc · listed 3 years ago
Status timeline
- Listed
Oct 13, 2023
- Data leaked
At a glance
- Group
- Ransomedvc
- Status
- Data leaked
- Country
- Brazil
- Listed on leak site
- Oct 13, 2023
About the victim
AI dossier — public-source company profileRodon (operating under rodoviariaonline.com.br) is a Brazilian online bus ticket marketplace that allows passengers to search, compare, and purchase intercity bus tickets across Brazil. The platform aggregates major Brazilian bus operators and offers routes connecting cities such as São Paulo, Rio de Janeiro, Curitiba, and Belo Horizonte. It also provides travel guides and promotional fare listings for consumers.
- Industry
- Online Bus Ticket Sales & Travel Platform
Attack summary
Severity: high — Data has been confirmed as published (disclosed status: data_published) and the group claims full server access including shared infrastructure affecting potentially multiple parties. A consumer-facing travel ticketing platform likely holds PII such as names, contact details, travel records, and payment information at scale, elevating severity to high.RansomedVC claims to have accessed everything from the company's main servers, including data belonging to other companies stored on shared infrastructure. A sample archive has been published as proof of the exfiltration.
Data the group says was taken
AI dossier — extracted from the leak post- Server data (main company servers)
- Shared/co-hosted third-party data
- Sample data archive (published)
The group's post references roughly 1 proof file.
What the group claims
Our group was able to access everything from the main company servers, and it happened that their data was on the server too(shared) Sample: https://qu.ax/LHRf.gz
Sources
- Victim siterodoviariaonline.com.br
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
