On April 4, 2026, Brazilian fiber-optic provider Alloha appeared on the leak site of the ransomware group known as thegentlemen. The company, which serves 1.5 million customers across 280 cities with a network spanning more than 140,000 km of optical fiber, is claimed to have had internal files exfiltrated during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch alloha.com
Get alerted the next time alloha.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about alloha.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes the incident as a ransomware deployment that resulted in data exfiltration. Thegentlemen posted a listing for alloha.com on their leak site, referencing internal documents. Alloha, founded in 2018 and headquartered in Sao Paulo, is the largest independent FTTH operator in Brazil. Public reporting indicates that the precise number of affected individuals remains unknown, and the exact types of customer records exposed have not been fully detailed in available sources. The listing appeared on April 4, 2026, consistent with the group’s typical practice of publishing victim data after failed ransom negotiations.
Why This Matters for You and Your Family
If you or anyone in your household uses Alloha internet service, your personal information may now sit in a ransomware leak repository. That data can include names, addresses, contact details, and account records tied to your home internet connection. Once exposed, these details become building blocks for identity theft, phishing campaigns, and unwanted solicitations. Your family’s daily reliance on home internet means a breach at your provider touches every device and every online activity linked to your address. Even when victim counts are listed as unknown, the scale of a company serving 1.5 million customers makes it likely that thousands of ordinary families are now at higher risk.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at one dataset. Criminals combine the newly released Alloha files with information from earlier breaches to create detailed profiles. An email address found in this leak can be matched to gaming accounts, social-media handles, or school records. This identity-chain process turns a single provider breach into long-term exposure. Public reporting shows that credential leaks like this one frequently cascade into account takeovers, especially for gaming platforms used by children. When a child’s gaming username is linked back to a parent’s leaked home address, the entire household becomes an easier target for harassment, swatting, or financial fraud.