DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Months after Lopes claimed no anomalies found in their system, hackers were in their system

Posted on July 25, 2022 by chum1ng0

Lopes is a Brazilian firm that provides real estate services in the form of brokerage and project and financial consulting. Lopes had what appears to be a data breach involving customer data earlier this year. But why the data breach may have continued for months after they denied finding any anomaly in their system is somewhat of a mystery.

In March 2022, Paulo Brito of CISO Advisor reported (machine translation below):

Now, images of documents supposedly owned by Lopes Real Estate and a link to a 2.15MB data file have been published on the Internet. The leak was made by a profile that identifies itself as Matron Group and claims to have gained access to one or more of the company’s servers.”

At that time, Lopes informed CISO Advisor that the files would have been exfiltrated from the franchisee network and “no anomalies have been detected in the network’s systems.”  Lopes declined to provide further details and DataBreaches was unable to find any follow-up disclosures by them. According to media coverage in Brazil cited by CISO Advisor, the breach would have been at Lopes Prime.

A few months later, an individual or individuals identifying as “Matrong” contacted DataBreaches.net by email, claiming to have 13 GB of data from Lopes.

Inspection of the sample files Matrong provided to this site revealed internal documents ranging in date from December 2021 to May 2022. Some documents related to customers or buyers.

The finding of data from May — months after the March report of a breach and after Lopes claimed they had found no anomalies in their network — raised questions. Was Lopes responsible for security on the franchisees’ systems, or was each franchisee responsible? What did Lopes do after finding that data had been stolen? Did it identify the franchisee? Did it ensure that any vulnerability or problem was addressed?

A sample sent to us by the hacker, redacted by databreaches.net, shows correspondence from May 2022, months after Lopes first claimed they had no evidence of any breach of their system.

 

DataBreaches contacted Lopes via email on July 12 and again on July 16 to ask about Matrong’s claims and to ask whether Lopes had notified anyone of this breach. No reply was received at all. DataBreaches also contacted two people whose personal information appears to have been stolen by the Matrong group to ask   whether the company had contacted them to notify them of this incident. No replies were received.

Although Lopes did not reply to our inquiries, DataBreaches did get some answers from email inquiries put to Matrong, who requested they be referred to as Boldenis77.

Boldenis77 claims they targeted Lopes because they were specifically looking for a real estate company. “We tried 4, one of them is Lopes. This type of company handles a lot of documents,” their spokesperson told DataBreaches.

And according to their spokesperson, Lopes was reportedly first attacked in February “through backdoor.”  The spokesperson stated that they did make a ransom demand on Lopes but that Lopes did not respond at all. “They didn’t respond us,” the spokesperson told DataBreaches, adding that it was Mr. Marcos Lopes and Mr. Cyro Naufel whom they had contacted.

Boldenis77 did not encrypt any files by the time DataBreaches communicated with them, and  reportedly has since lost access.

At this time, then, DataBreaches does not know if any consumers whose personal information was acquired has been notified by Lopes.  Nor does DataBreaches know if any data has been leaked or sold.

If you are a customer of Lopes, have you been notified by them of any breach? Contact the reporter at Chum1ngo@protonmail[.]com.


Additional reporting and editing by Dissent.


Related:

  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Toys “R” Us Canada customers notified of breach of personal information
  • Gatineau gymnastics centre warns members of possible data breach
  • Data breach in 42 Latvian municipalities: DVI imposes 300,000 euro fine on ZZ Dats
  • Kaufman County's data breach was their second one in three weeks
Category: Breach IncidentsBusiness SectorHackNon-U.S.

Post navigation

← An Entire Canadian Town Is Being Extorted By Ransomware Cyber Criminals
Digital security giant Entrust breached by ransomware gang →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others
  • Draft UK Cyber Security and Resilience Bill Enters UK Parliament
  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Maryland Privacy Crackdown Raises Bar for Disclosure Compliance
  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.