Ransomware victim disclosure
← All victimsSICOL – JS Cobranças e Serviços
listed as Sicol · Claimed by spacebears · listed 10 hours ago
Status timeline
- Listed
Jun 4, 2026
- Data leaked
At a glance
- Group
- spacebears
- Status
- Data leaked
- Country
- BR
- Sector
- Manufacturing
- Listed on leak site
- Jun 4, 2026
About the victim
AI dossier — public-source company profileSICOL – JS Cobranças e Serviços is a Brazilian debt collection and credit management company based in Aracaju, Sergipe. They provide integrated solutions combining digital automation with humanized customer support to help businesses recover debts and optimize sales workflows, serving multiple clients across their credit and collections cycle.
- Industry
- Debt Collection & Credit Management Services
- Address
- Edifício Norcon, R. João Pessoa, 71, Sala 405, 4º Andar, Centro, Aracaju, SE 49010-130, Brazil
Attack summary
Severity: high — Confirmed exfiltration of PII (employee and client personal information) and financial documents from a debt collection company. This affects both the company's staff and potentially thousands of consumer/business clients whose financial data is at risk.The spacebears group claims to have exfiltrated personal information of employees and clients, financial documents, and other files from SICOL's systems.
Data the group says was taken
AI dossier — extracted from the leak post- Personal information of employees
- Personal information of clients
- Financial documents
- Other files
What the group claims
SICOL – JS Cobranças e Serviços is a Brazilian company specializing in debt collection, credit management, and sales services. They blend digital automation with humanized customer support to help businesses recover debts and optimize their sales workflows.-Personal information of employees and clients -Financial documents -Other files https://***.com.br/
The leak post
captured from the group's siteSICOL – JS Cobranças e Serviços is a Brazilian company specializing in debt collection, credit management, and sales services. They blend digital automation with humanized customer support to help businesses recover debts and optimize their sales workflows. -Personal information of employees and clients -Financial documents -Other files
Screenshot of the leak post

Sources
Source
Indexed 10 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
