Ransomware victim disclosure
← All victimsSESI - Serviço Social da Indústria
listed as sesi.org.br · Claimed by Lockbit5 · listed 3 months ago
Status timeline
- ListedMar 30, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileSESI (Serviço Social da Indústria) is a Brazilian para-governmental organization managed by the National Confederation of Industry (CNI) that provides quality education, health, culture, and leisure services to industrial workers and their families across Brazil. It operates thousands of units nationwide, offering programs ranging from basic and adult education (EJA) to healthcare clinics and sports facilities. SESI is part of the 'Sistema Indústria' alongside SENAI, CNI, and IEL.
- Industry
- Education, Health & Social Services (Industrial Workers)
- Address
- Setor Bancário Norte, Quadra 1, Bloco C, Ed. Roberto Simonsen, Brasília, DF, Brazil
- Employees
- 10000+
- Founded
- 1946
Attack summary
Severity: critical — SESI serves millions of industrial workers and their families across Brazil, holding regulated PII, health records, and educational records at large scale. Data publication confirmed by 'data_published' status, involving a major national social services institution with sensitive personal and medical data.LockBit 5 claims to have attacked SESI and published data (disclosed status: data_published), suggesting exfiltration of organizational data; no ransom amount was stated and specific data volume was not disclosed in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal records
- Student/beneficiary records
- Health service records
- Administrative documents
- Internal organizational data
What the group claims
SESI provides quality education, health, and cultural services aimed at improving the quality of lif...
Sources
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

