Ransomware victim disclosure
← All victimsRodon (rodoviariaonline.com.br)
listed as rodoviariaonline.com.br · Claimed by ransomed · listed 3 years ago
Status timeline
- Listed
Oct 13, 2023
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileRodon (operating via rodoviariaonline.com.br) is a Brazilian online platform for purchasing intercity bus tickets, connecting major cities such as São Paulo, Rio de Janeiro, Curitiba, and Belo Horizonte. The platform aggregates routes from the main Brazilian bus companies and offers promotional fares. It also provides travel guides and destination content for passengers.
- Industry
- Online Bus Ticket Sales & Travel Services
Attack summary
Severity: medium — Data exfiltration is claimed and a sample has been published, indicating confirmed data disclosure. However, the nature and scale of the data (e.g., customer PII, payment records) is not explicitly described, and no ransom or data size is stated, limiting the severity assessment to medium.The group 'ransomed' claims to have accessed the company's main servers, including data belonging to the company and possibly co-hosted third parties (described as 'shared' server data), and has published a sample file as proof of exfiltration.
Data the group says was taken
AI dossier — extracted from the leak post- Server data (unspecified)
- Shared server data (potentially third-party)
- Sample file published (compressed archive)
The group's post references roughly 1 proof file.
What the group claims
Our group was able to access everything from the main company servers, and it happened that their data was on the server too(shared) Sample: https://qu.ax/LHRf.gz
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
