Soma Soluções em T.I. Data Breach

Alleged

Ransomware claim involving Soma Soluções em T.I.

Published: Sep 29, 2026 m3rx
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Soma Soluções em T.I.
Industry
Professional Services
Threat Actor
m3rx
Date of Incident
Sep 29, 2026

Executive Summary

On September 29, 2026, the m3rx ransomware group added Soma Soluções em T.I., a Brazilian IT services company, to its dark web leak portal. SOCRadar’s Dark Web Monitoring service detected this listing. The incident potentially connects to an administrative credential for the subdomain adm[.]somasolucoes.com that was harvested by an infostealer around December 2025. This credential, associated with a non-corporate email address, remained unrotated for approximately five months. While the direct link between the dormant credential and the ransomware claim is unconfirmed, the overlapping timeline suggests a possible connection. In the 60 days preceding this listing, m3rx claimed seven other victims. These victims spanned the Professional Services, Technology, and Retail & E-Commerce industries across the United States, Brazil, and Canada. Notable recent victims include CPACB, Interconnect Computer Cabling Services Inc., Otero Geeza Law P.A., and Tecnologías de Código Abierto S.L. Soma Soluções em T.I.’s inclusion marks the group’s second Brazilian victim and aligns with their pattern of simultaneously targeting small IT and professional services firms in the Americas.

Technical Analysis

SOCRadar’s stealer-log telemetry identified two records pertaining to somasolucoes[.]com. The first record indicated an employee credential associated with Locaweb, identified as a third-party hosting provider. The second record revealed a non-corporate email credential linked to the administrative subdomain adm[.]somasolucoes.com, with its origin dating back to December 2025. The credential associated with the administrative subdomain is of particular concern. External hosting provider access is significant, but unrotated access to an organization’s own administrative infrastructure for nearly five months represents a considerably higher risk. Ransomware operators frequently exploit such footholds—dormant, unmonitored credentials on administrative panels—to facilitate lateral movement within a network and to stage data prior to encryption. The fact that the discovered admin credential remained unrotated at the time of m3rx’s listing is a critical detail that warrants immediate security attention. Audit authentication logs for the adm[.]somasolucoes.com subdomain, specifically from December 2025 onwards, should be a priority. Organizations should scrutinize these logs for any access patterns that deviate from normal business hours or originate from unexpected IP ranges. Both identified credential records should be treated as compromised, and immediate rotation of affected credentials is recommended.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.