Ransomware victim disclosure
← All victimscoemi.com.br
Claimed by Krybit · listed 4 hours ago
Status timeline
- ListedJun 19, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileCoemi Imóveis is a Brazilian real estate brokerage and property management company established in 1983, based in Brasília, Distrito Federal. Operating for 41 years, it specializes in buying, selling, and renting residential and commercial properties across Brasília's premium neighborhoods (Asa Norte, Lago Norte, Sudoeste, etc.). The company serves both landlords and tenants through a digital platform and physical office.
- Industry
- Real Estate & Property Management
- Address
- Quadra CLN 305, Bloco D, Lojas 12 e subsolos 3–27, Asa Norte, Brasília, DF, Brazil
- Founded
- 1983
Attack summary
Severity: medium — Real estate firm data exposure involving client records and financial/property information; no explicit confirmation of regulated PII exfiltration at scale or critical infrastructure disruption; data published without stated ransom suggests post-compromise disclosure.The Krybit ransomware group claims to have compromised Coemi Imóveis and exfiltrated data. The leak post indicates data publication, though specific data categories and encryption status are not detailed in the truncated disclosure.
Data the group says was taken
AI dossier — extracted from the leak post- client records
- property listings
- financial transactions
- tenant/landlord information
What the group claims
Coemi Imóveis is a Brazilian real estate company with 41 years of tradition in Brasília, Distrito Federal, Brazil, fou...
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

