Ransomware victim disclosure
← All victimsescriba.com.br
Claimed by Threeam · listed 2 years ago
Status timeline
- ListedMay 16, 2024
- Data leakeddate unknown
At a glance
- Group
- Threeam
- Status
- Data leaked
- Country
- Brazil
- Sector
- Technology
- Listed on leak site
- May 16, 2024
About the victim
AI dossier — public-source company profileEscriba Informática is a Brazilian technology company specializing in software solutions and systems for notarial offices (cartórios extrajudiciais) across Brazil. With over 35 years of experience, they serve 400+ notarial offices and operate in 20 states plus the Federal District, providing integrated platforms for document registration, notarization, civil records, and financial management.
- Industry
- Legal Technology & Notarial Software
- Employees
- 100
- Founded
- 1989
Attack summary
Severity: high — Escriba's systems manage sensitive legal and civil records across 400+ notarial offices serving thousands of citizens. Compromise of such infrastructure could expose regulated personal data (civil records, property registrations, document authentication) at scale across Brazil's legal system, even without explicit proof files published.The Threeam group claims to have compromised Escriba's systems and exfiltrated data. The leak post references the company's business operations but provides no explicit details of what data was stolen or operational impact.
Data the group says was taken
AI dossier — extracted from the leak post- notarial office data
- legal documents and records
- client information
- system databases
What the group claims
Somos a maior empresa em sistemas e soluções para cartórios extrajudiciais. Atuamos no desenvolvimento de softwares e soluções inovadoras para a gestão de cartórios extrajudiciais, tabelionato de notas, tabelionato de protestos, ofício de...
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

