FRM Fábrica de Rolamentos e Mancais Data Breach

Alleged

Ransomware claim involving FRM Fábrica de Rolamentos e Mancais

Published: Aug 30, 2026 ZaWoo
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
FRM Fábrica de Rolamentos e Mancais
Industry
Manufacturing
Threat Actor
ZaWoo
Date of Incident
Aug 30, 2026

Executive Summary

The ZaWoo ransomware group has claimed FRM Fábrica de Rolamentos e Mancais as a victim, announcing the alleged breach on its leak site on August 30, 2026. The group asserts unauthorized access to the systems and data of the Brazilian manufacturing firm, identified by the domain frm[.]ind[.]br. While independent verification of the breach has not been completed, the claim is supported by evidence of compromised credentials. This includes 20 credentials spanning employee systems and corporate platforms, representing exposure over an eight-month period prior to the leak-site listing. The manufacturing sector, particularly in regions with established industrial bases like Brazil, can be attractive targets for ransomware groups due to the potential for significant operational disruption and the value of intellectual property. Over the past 60 days, ZaWoo has listed 16 victims, with a primary focus on Germany (DE) and Austria (AT), predominantly targeting the Technology and Manufacturing industries. FRM Fábrica de Rolamentos e Mancais aligns with ZaWoo’s typical sector targeting. Although Brazil is geographically outside ZaWoo’s usual primary operational areas, the group’s history suggests deliberate victim selection rather than indiscriminate attacks. This indicates that FRM Fábrica de Rolamentos e Mancais may have been specifically targeted based on criteria that align with the group’s strategic objectives, potentially due to its role within the manufacturing supply chain or other perceived vulnerabilities.

Technical Analysis

SOCRadar CTI’s analysis of stealer-log data returned a “severe_exposure_in_sample” verdict for FRM Fábrica de Rolamentos e Mancais. The telemetry identified 11 employee credentials associated with the organization’s systems and an additional 9 corporate credentials linked to services such as Microsoft, webmail, and ITGlue. The timestamps for these compromised credentials range from December 5, 2025, to August 3, 2026, indicating an exposure period of over eight months preceding the ransomware group’s leak-site listing. The exposure of ITGlue credentials is particularly noteworthy, as access to this managed documentation platform can provide an adversary with detailed information about the organization’s network infrastructure and operational procedures. This intelligence can significantly accelerate lateral movement and the staging of stolen data, facilitating a more effective ransomware deployment. All affected credentials require immediate rotation across all platforms, and a thorough review of ITGlue access logs should be conducted to identify any unauthorized activity. Continued monitoring of dark web forums and stealer-log feeds for any further disclosures related to FRM Fábrica de Rolamentos e Mancais is recommended. Proactive credential hygiene measures, including robust password rotation policies and multi-factor authentication enforcement across all systems, are critical. Furthermore, a review of Microsoft 365, VPN, and remote-access portal activity logs should be undertaken to detect any anomalous login attempts or unusual access patterns that may indicate ongoing compromise attempts or established persistence.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.