Ransomware victim disclosure
← All victimsAlloha Fibra
listed as alloha.com · Claimed by Thegentlemen · listed 2 months ago
Status timeline
- ListedApr 4, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- United States
- Sector
- Consumer Services
- Listed on leak site
- Apr 4, 2026
About the victim
AI dossier — public-source company profileAlloha Fibra is the largest independent FTTH (Fiber To The Home) broadband operator in Brazil, founded in 2018 and headquartered in São Paulo. The company operates a network of over 140,000 km of optical fiber and serves approximately 1.5 million customers across 280 cities throughout Brazil.
- Industry
- Fiber-to-the-Home (FTTH) Broadband Internet Services
- Address
- São Paulo, Brazil
- Founded
- 2018
Attack summary
Severity: high — Alloha Fibra is a large telecommunications/broadband provider with 1.5 million customers, making any data publication potentially significant in scale. Published data from a major ISP likely includes customer PII, account data, and sensitive business information at scale, warranting a high severity rating. Critical would require confirmed regulated/sensitive data categories explicitly enumerated.The group 'thegentlemen' claims to have attacked Alloha Fibra and the disclosure status is listed as data_published, indicating exfiltration and publication of company data, though the leak post does not explicitly detail the specific types of data exfiltrated or whether encryption was involved.
What the group claims
alloha.com zoominfo.com/c/alloha-fibra/1318975911 Alloha is the largest independent FTTH (Fiber To The Home) operator in Brazil, founded in 2018 and headquartered in Sao Paulo. The company has a network of over 140,000 km of optical fiber and serves 1.5 million customers across 280 cities
Sources
- Victim sitealloha.com
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

