Ransomware victim disclosure
← All victimsSoma Soluções (SNW Tecnologia da Informação LTDA)
listed as somasolucoes.com · Claimed by M3Rx · listed 5 hours ago
Status timeline
- ListedSep 29, 2026
- Data leakeddate unknown
At a glance
- Group
- M3Rx
- Status
- Data leaked
- Country
- Brazil
- Sector
- Professional Services
- Listed on leak site
- Sep 29, 2026
About the victim
AI dossier — public-source company profileSoma Soluções is a Brazilian IT services and software company based in Araras, São Paulo. They develop enterprise solutions including ERP systems, web development, telephony billing software, mobile applications, and IT infrastructure services. The company operates a subsidiary e-commerce platform (SUM STORE) selling IT and telecommunications equipment.
- Industry
- IT Services & Software Development
- Address
- Araras, SP, Brazil
Attack summary
Severity: low — The leak post provides no proof files, screenshots, or specific data inventory. The post is a bare listing/announcement with a contact method for interested buyers. No confirmation of data exfiltration or encryption-induced disruption is evident from the truncated post.The m3rx group claims to have compromised Soma Soluções and lists the data for sale. The leak post contains minimal detail; no specific data categories or operational impact are stated beyond the sale advertisement.
What the group claims
+55 1935472050 , Soma Soluções em T.I. specializes in corporate IT solutions, offering a flexible and cost-effective ERP system tailored to the unique needs of businesses. Their services include web development, mobile applications, technical support, and digital marketing, aimed at simplifying business management and reducing operational costs. The company also provides a virtual store for IT and telecommunications equipment, enhancing brand visibility online. Their target clients are businesses seeking to optimize their operations and improve efficiency through innovative technology solutions. Stolen: --
The leak post
captured from the group's siteIf you are interested in this data, please contact our support.Tox: 9A1217BEDA4AB77052A25D17CB6FFB34AFA2BE462E607F2FD8E1DF1DDD4CA16A64E18B1A0BF2
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

