Grupo Rái Data Breach

Alleged

Ransomware claim involving Grupo Rái

Published: Aug 3, 2026 LockBit5
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Grupo Rái
Industry
Business Services
Threat Actor
LockBit5
Date of Incident
Aug 3, 2026

Executive Summary

Grupo Rái, a company based in Brazil, has been listed as a victim on the LockBit5 ransomware group’s dark web portal, published on August 3, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. The organization is recorded without a specific sector classification in SOCRadar’s dataset, operating out of Brazil. It arrives as part of a large single-day batch of LockBit5 listings spanning several continents, and Brazil is the country that appears most frequently in the group’s recent output. In the 60 days prior to this listing, LockBit5 has claimed 76 other victims across its leak portal. The group has shown a strong targeting pattern in the Manufacturing, Business Services, and Hospitality and Tourism sectors. Geographically, its victims are concentrated in Brazil, the United States, and Germany, with the Netherlands and Thailand close behind. Other recent LockBit5 listings that overlap with Grupo Rái’s profile — Brazilian organizations across several verticals — include State Secretariat of Health of Mato Grosso, 5 de Agosto, Sweetome, and Grupo Detoni. The Brazilian cluster is one of the more consistent features of LockBit5’s recent activity, and Grupo Rái fits it directly.

Technical Analysis

Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a notable exposure for the rai.com.br domain. The queried slice of twenty-five records contained one confirmed corporate employee credential on organization-owned infrastructure, eighteen records tied to external or customer accounts on a company subdomain, one corporate identity on a third-party SaaS platform, and five records that could not be classified due to username masking. The bulk of the volume points at a customer-facing cooperative portal’s login and registration paths, which for a consumer-accessible service is an expected pattern. The more operationally relevant signal is the single corporate identity appearing on an external business platform in late July, which the analysis read as a workstation-compromise indicator. The freshness window is very wide — running from April 2024 through 3 August 2026, the listing date itself — with clear long-tail characteristics and no sign of rotation. The dominant profile was assessed as mixed. For ransomware groups such as LockBit5, infostealer-harvested credentials are a well-documented initial access vector: operators or initial access brokers source fresh logs from underground marketplaces, validate the corporate credentials, and use them to log into Microsoft 365, VPN, or remote-access portals before deploying ransomware. While the stealer-log evidence here does not confirm that these specific credentials were used by LockBit5, the pattern is consistent with the kill chain typically observed for this class of incident — a corporate credential harvested from an infected endpoint within days of the listing is the sequence most often seen. The large volume of customer-account records is a separate exposure that warrants its own notification and account-review track, independent of the ransomware claim.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.