On November 20, 2025, Brazilian ERP provider CIGAM Software Corporativo Ltda appeared on the leak site of the coinbasecartel ransomware group, with internal files reportedly exfiltrated during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch CIGAM Software Corporativo Ltda
Get alerted the next time CIGAM Software Corporativo Ltda files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about CIGAM Software Corporativo Ltda’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes the listing on the coinbasecartel leak site hosted via ransomware.live. The company develops and sells an ERP platform used by medium and large organizations for financial management, inventory, sales, and other core operations. Public reporting indicates that attackers gained access, exfiltrated internal files, and later published the data after CIGAM did not meet their demands. Exact victim counts inside the company remain unknown, and the precise volume or sensitivity of the files has not been independently verified beyond the group’s own claims. The incident follows the group’s typical pattern of initial access, data theft, and public extortion.
Why This Matters for You and Your Family
When a company that handles business records for other organizations is breached, the ripple effects often reach ordinary people. Employee records, vendor contracts, customer invoices, or partner contact details inside those internal files can contain names, addresses, tax IDs, phone numbers, and email accounts that belong to you or members of your household. Once exposed, this information rarely stays contained. It can be sold, combined with other leaks, and used to target you with identity theft, phishing, or harassment. Your family’s privacy is directly affected even if you have never heard of CIGAM before today.
The Doxxing and Identity-Chain Implications
Ransomware leaks like this one frequently accelerate doxxing chains. A single exposed email or phone number from corporate files can be cross-referenced with gaming accounts, social-media handles, or family-member profiles. Attackers or opportunistic criminals then map these connections to build a complete picture of your household. Credential leaks of this nature commonly cascade into account takeovers on personal services, including gaming platforms used by children. What begins as a corporate ransomware incident can quickly become personal when the same password or contact detail appears in multiple places.