Skip to main content

Ransomware victim disclosure

All victims

VALID Certificadora Digital Ltda

listed as validcertificadora.com.br · Claimed by Crosslock · listed 3 years ago

$100M
Ransom
demanded
39m
Age
since listed · data leaked

Status timeline

  1. ListedApr 17, 2023
  2. Data leakeddate unknown

At a glance

Status
Data leaked
Country
Brazil
Listed on leak site
Apr 17, 2023
Ransom demanded
$100M

About the victim

AI dossier — public-source company profile

VALID Certificadora Digital Ltda is a Brazilian digital certification authority headquartered in São Paulo, SP. The company issues and manages digital certificates for individuals and legal entities, including e-CPF, e-CNPJ, SSL certificates, and cloud-based certificate solutions. It serves multiple sectors including legal, financial, and healthcare, and operates a certificate authority infrastructure under Brazilian ICP-Brasil standards.

Industry
Digital Certification & PKI Services
Address
São Paulo, SP, Brazil
Employees
501-1000

Attack summary

Severity: critical — VALID Certificadora is a certificate authority handling regulated identity data (CPF, CNPJ) for individuals and legal entities across legal, financial, and healthcare sectors in Brazil. A breach of a CA operator's systems represents critical risk: potential exposure of identity credentials, private keys, and PII at scale for thousands of certificate holders, with downstream trust infrastructure implications.

The Crosslock ransomware group claims an attack on VALID Certificadora Digital Ltda and has published data. The post references a company with $100M–$250M in revenue and 501–1,000 employees, though no specific data size or exfiltration volume is stated.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • Digital certificate records
  • Customer PII (CPF/CNPJ holders)
  • SSL certificate management data
  • Business/legal entity registration data
  • Healthcare professional certificate data
  • Financial sector client data
  • Internal company documents

What the group claims

VALID Certificadora Digital Ltda is a company that operates in the Farming industry. It employs 501-1,000 people and has $100M-$250M of revenue. The company is headquartered in São Paulo, Sp, Braz...

Sources

Source

Indexed 3 years ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About Crosslock

Crosslock is an obscure ransomware group that emerged in April 2023, appearing to be financially motivated based on typical ransomware group patterns. The group's country of origin and operational structure remain unknown due to limited public documentation from major threat intelligence sources. Based on available data, the group has demonstrated minimal operational scale with only one documented victim, suggesting either highly targeted operations or limited operational capacity. The group appears to focus its targeting efforts primarily on Brazilian entities, though the specific attack methodology, encryption techniques, and extortion tactics employed by Crosslock have not been publicly documented by major cybersecurity firms or law enforcement agencies. No major campaigns, high-profile victims, or significant ransoms have been publicly attributed to this group by reputable sources. The current operational status of Crosslock remains unclear due to the limited threat intelligence available on this group. The group has been linked to 1 public disclosures across our corpus. First observed on a leak site on April 17, 2023. The operation is currently inactive.

Timeline of this disclosure

  • April 17, 2023validcertificadora.com.br listed by Crosslockon the group's public leak site
Ransom demanded
$100M

Sector and geography

This disclosure adds to ransomware activity in the Technology sector, which has 3,563 disclosures indexed across all operators we track. Geographically, validcertificadora.com.br is reported in Brazil, a country with 404 ransomware disclosures in our corpus.

If your organisation is affected

A listing by Crosslock means validcertificadora.com.br appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Report the incident to your national CERT, CERT.br (Brazil), as required for your jurisdiction.
  • Monitor for the data appearing on Crosslock's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.