Quick Summary
AllegedExecutive Summary
PontoBR Sistemas, a technology company based in Brazil, has been listed as a victim on the SpaceBears group’s dark web portal, with the listing published on August 5, 2026. This information was identified through SOCRadar’s Dark Web Monitoring service. The company operates in the software and systems sector, providing hosted applications to business customers. Notably, it is the sole Brazilian entry in SpaceBears’ recent victim population. The nature of PontoBR Sistemas’ business, offering hosted software solutions, could make it an attractive target for ransomware and extortion activities. In the 60 days preceding this listing, SpaceBears claimed six other victims across its leak portal. This makes SpaceBears one of the smaller operations observed by volume. The group’s targeting pattern has predominantly focused on the technology sector, with single entries also noted in the energy and manufacturing industries. Geographically, its victims are spread across the United States, Cameroon, and Poland, in addition to Brazil, without a clear concentration in any single region. Other recent victims listed by SpaceBears that align with PontoBR’s technology profile include StellarRAD Systems, Turbosoft, Techpol-System, and Salters propane. Given the limited number of listings on the portal, the technology sector appears to be the primary targeting pattern supported by the available data, and PontoBR Sistemas fits this profile.
Technical Analysis
SOCRadar’s stealer-log telemetry revealed a credential exposure linked to the pontobrsistemas.com.br domain. The analysis covered 25 records, all of which authenticated against organization-owned subdomains, including numbered application hosts and one named service. However, the usernames associated with these records were either numeric or generic handles, or personal email addresses, with none clearly attributable to a corporate identity. For a company that provides hosted software, this composition suggests that the exposed credentials are for end-user accounts on customer-facing application instances, rather than employee credentials. This indicates a potential customer account takeover scenario. For ransomware groups like SpaceBears, credentials harvested by infostealers are a well-documented method for gaining initial access. Threat actors or initial access brokers typically source these logs from underground marketplaces, validate the corporate credentials, and then use them to access systems such as Microsoft 365, VPNs, or remote-access portals to deploy ransomware. While this specific sample of stealer-log data did not yield corporate credentials, thus not directly supporting a direct ransomware deployment path via stolen employee credentials, it does highlight a significant risk for PontoBR Sistemas. Given that PontoBR provides hosted software, the exposure of tenant credentials poses a downstream risk to its customers who utilize these instances. Security teams should interpret this finding as evidence of credential leakage across the served application estate. It is recommended that CTI teams continue monitoring for corporate-level exposure that this limited sample would not have surfaced. Given the nature of the exposed credentials and the ransomware group’s typical modus operandi, it is advisable for PontoBR Sistemas to continue dark web monitoring, conduct proactive credential hygiene checks, rotate passwords, and review multi-factor authentication settings. Monitoring for activity on alternate corporate domains and reviewing logs for Microsoft 365, VPNs, and remote-access portals are also crucial steps.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.