Jota Joias Premium Data Breach

Alleged

Ransomware claim involving Jota Joias Premium

Published: Jul 19, 2026 Nova
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Jota Joias Premium
Industry
Consumer Services
Threat Actor
Nova
Date of Incident
Jul 19, 2026

Executive Summary

Jota Joias Premium, a consumer services organization based in Brazil, has been listed as a victim on the Nova ransomware group’s dark web leak portal, with the entry published on July 19, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The company operates in the consumer services space, according to the sector classification captured at the time of listing. The entry places Jota Joias Premium among the most recent additions to Nova’s victim population. In the 60 days preceding this listing, Nova has claimed 37 other victims across its leak portal. The group has concentrated its efforts on the technology, transportation/logistics, and education sectors, with a geographical concentration of victims in Indonesia, Australia, and the United States. Other recent Nova listings that share similarities with Jota Joias Premium’s profile include One Believing Interiors, FMZ Tecnologia em Sistemas, Dephub, and meralmanisa. Jota Joias Premium aligns with the group’s opportunistic pattern of targeting consumer services and mid-market entities, rather than indicating a deviation from their typical behavior.

Technical Analysis

Initial access correlation against SOCRadar’s stealer-log telemetry surfaced a severe exposure for the jotajoiaspremium.com.br domain. The returned sample contained 21 records showing corporate users on third-party services, and 2 records associated with customer, supplier, or external accounts on organization-owned systems. High-value endpoints observed included an administrative user-management endpoint on the corporate domain and a corporate account on the Atlassian identity provider. The dominant profile is workstation compromise risk, with sample freshness spanning June 23 to July 10, 2026. For ransomware groups such as Nova, infostealer-harvested credentials are a well-documented initial-access vector. Operators or initial-access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. While the stealer-log evidence here does not confirm that these specific credentials were used by Nova, the pattern is consistent with the kill chain typically observed for this class of incident. CTI teams should prioritize credential rotation, MFA enforcement, and endpoint review for the exposed accounts, and treat the exposure as a live risk rather than a historical artifact.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.