Quick Summary
AllegedExecutive Summary
LockBit 5 listed Camorim Serviços Marítimos, a Brazilian maritime services provider with over 30 years of sector experience, on its dark web portal on September 29, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring service. Given the critical nature of maritime services and logistics, Camorim Serviços Marítimos likely represents a valuable target for ransomware actors seeking to disrupt operations or extort significant ransoms. LockBit 5 is identified as a highly active ransomware operation, claiming 48 victims in the preceding 60 days. Their activity is primarily concentrated in the United States, Germany, and the Netherlands, with a focus on the Professional Services, Manufacturing, and Healthcare industries. Other recent victims with potential geographic or sector overlap include Anery Home Care, AmorSaúde, Grupo Rái, and CO.R.I.S. S.r.l. Camorim’s listing indicates LockBit 5’s continued expansion into South America, specifically targeting the maritime and logistics sectors.
Technical Analysis
SOCRadar’s stealer-log analysis of camorim[.]com.br revealed 25 records spanning an 11-month period, from October 2025 to August 2026. These records were categorized across different platforms and user types. The identified records include six related to Microsoft 365 identity endpoints, encompassing four distinct employee accounts, and two related to Office 365 SMTP infrastructure. Additionally, two records were found for the TOTVS Fluig enterprise identity system. The analysis also uncovered five records associated with payment and financial processing platforms. The collected telemetry was further broken down into classifications: 11 records categorized as “category A,” indicating employee credentials on organization-controlled systems, and another 11 records representing corporate users on third-party services. The significant exposure window of 11 months, from October 2025 to August 2026, implies a sustained period of risk. If these credentials were compromised and utilized early in this timeframe, it suggests potential access to Microsoft 365 and SMTP infrastructure for nearly a year prior to the LockBit 5 listing. The presence of compromised SMTP infrastructure creates a secondary risk of enabling phishing campaigns targeting Camorim’s partners and shipping clients, potentially extending the impact through a supply-chain vector. Furthermore, the involvement of the TOTVS Fluig platform, a critical Brazilian enterprise system for identity management and business process orchestration, presents a broader potential attack surface within the maritime and logistics context. While the stealer-log data does not definitively confirm LockBit 5’s use of these specific credentials, the extensive exposure window establishes a significant and sustained risk that should be treated as an active incident until proven otherwise. The recommended investigation sequence includes force-rotating Microsoft 365 accounts, auditing SMTP relay configurations, reviewing TOTVS Fluig access logs, performing endpoint forensics on affected machines, and notifying payment platform providers of potential credential compromise.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.