Ransomware victim disclosure
← All victimsSelpe Consultoria de RH
listed as gruposelpe.com.br · Claimed by Lockbit5 · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Brazil
- Sector
- Business Services
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileSelpe Consultoria de RH is a Brazilian HR consulting and people management firm with approximately 60 years of market experience. The company offers services across the full talent lifecycle including recruitment and selection, executive search, temporary staffing, trainee programmes, and HR advisory. It operates multiple offices across Brazil (Belo Horizonte, São Paulo, Recife, Contagem, Conselheiro Lafaiete, Uberlândia) and is a member of the NPA WorldWide executive search network.
- Industry
- Human Resources Consulting & Talent Management
Attack summary
Severity: high — Data has been confirmed as published (data_published status) by the threat actor. As an HR and recruitment consultancy, Selpe's systems likely contain substantial PII for candidates and client employees across Brazil, including CVs, identification documents, and employment records, constituting significant sensitive personal data exposure at scale.LockBit 5 claims to have attacked Selpe Consultoria de RH, with the disclosure status listed as data_published, indicating that exfiltrated data has been released. The specific categories of data published were not detailed in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- HR and recruitment records
- Candidate personal data
- Client company information
- Employee/people management data
- Internal business documents
What the group claims
Selpe Consultoria de RH specializes in human resources and people management, offering services in r...
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

