RANSOMWARE VICTIMTRANSPORTATION/LOGISTICS⚠ DUPLICATE CLAIM
Correios
correios.com.br
coinbasecartel📍 Brazil (BR)📅 April 8, 2026
8
same group
Attack Intelligence
Correios was compromised in a ransomware attack attributed to coinbasecartel in April 2026. The organization, operating in the Transportation/Logistics sector in Brazil, was added to the group's data leak site as part of an extortion campaign.
coinbasecartel operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Additional Details
Other Victims — coinbasecartel (8)
Quick Facts
CountryBrazil (BR)
SectorTransportation/Logistics
Attack DateApr 8, 2026
Domaincorreios.com.br
Intel Sourceransomlook
StatusDUPLICATE CLAIM
Threat Group
External Links
Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.