Skip to main content

Ransomware victim disclosure

All victims

Redeplast

listed as redeplastrs.com.br · Claimed by Blackfield · listed 5 hours ago

Today
Age
since listed · data leaked

Status timeline

  1. ListedJul 3, 2026
  2. Data leakeddate unknown

At a glance

Status
Data leaked
Country
Brazil
Listed on leak site
Jul 3, 2026

About the victim

AI dossier — public-source company profile

Redeplast is a Brazilian footwear and handbag manufacturer founded in 2002, based in Novo Hamburgo, Rio Grande do Sul. With over 20 years of experience, the company produces PVC-injected shoes and bags for major national and international brands, exporting to Europe and North America. The facility operates with 350+ employees and produces approximately 9,000 units daily across a 5,000 m² manufacturing plant.

Industry
Footwear & Handbag Manufacturing (PVC-injected)
Address
Novo Hamburgo, RS, Brazil
Employees
350
Founded
2002

Attack summary

Severity: medium — Data published by the group with disclosed status, but no specific evidence of regulated/sensitive data (PII at scale, financial, medical) is mentioned in the available excerpt. No proof file count is documented. The company handles customer/client data and business records of moderate sensitivity in a manufacturing context.

Blackfield claims to have breached Redeplast and published exfiltrated data. The specific data categories compromised are not detailed in the truncated leak post excerpt.

medium

Data the group says was taken

AI dossier — extracted from the leak post
  • Business records
  • Client information
  • Operational data

What the group claims

Redeplast is a Brazilian footwear manufacturer with over 20 years of experience in the industry. The...

Sources

Source

Indexed 5 hours ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About Blackfield

Blackfield is a ransomware group first observed in June 2026 with an apparent financial motivation, though its limited operational history makes comprehensive characterization difficult based on currently available public reporting. No attribution to a specific country of origin has been publicly documented by CISA, the FBI, Mandiant, or other reputable threat intelligence sources at this time, and it remains unclear whether the group operates as a Ransomware-as-a-Service model or as an independent closed actor. Based on available victimology data, the group has demonstrated a targeting pattern focused on the manufacturing sector in Taiwan, though with only one confirmed victim on record, definitive conclusions about consistent attack methodology, preferred initial access vectors, or encryption tooling cannot be responsibly stated without further corroborated public reporting. No notable high-profile campaigns, record ransom demands, or law enforcement actions against this group have been publicly documented as of this writing. Given its very recent emergence in mid-2026 and minimal victim count, Blackfield should be considered an emerging or nascent threat actor whose operational scope, capabilities, and affiliations warrant continued monitoring as additional intelligence becomes available. The group has been linked to 2 public disclosures across our corpus. First observed on a leak site on June 29, 2026; most recent post July 3, 2026. The operation is currently active.

Timeline of this disclosure

  • July 3, 2026redeplastrs.com.br listed by Blackfieldon the group's public leak site

Other recent disclosures by Blackfield

Blackfield has been linked to 2 public victims on Darkfield. A sample of the most recent:

See the full Blackfield dossier →

Sector and geography

This disclosure adds to ransomware activity in the Manufacturing sector, which has 3,678 disclosures indexed across all operators we track. Geographically, redeplastrs.com.br is reported in Brazil, a country with 199 ransomware disclosures in our corpus.

If your organisation is affected

A listing by Blackfield means redeplastrs.com.br appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Report the incident to your national CERT, CERT.br (Brazil), as required for your jurisdiction.
  • Monitor for the data appearing on Blackfield's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.