Escriba.com.br was listed on the leak site of the threeam ransomware group on May 16, 2024. The Brazilian company, which develops software and management systems for extrajudicial notaries, cartórios, and related offices, is claimed to have had internal files exfiltrated during a ransomware attack. The leak-site listing does not specify the number of affected individuals or the exact volume or types of data taken beyond claiming that internal files were stolen.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch escriba.com.br
Get alerted the next time escriba.com.br files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about escriba.com.br’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The primary disclosure on the threeam leak site states that Escriba suffered a ransomware incident and that attackers successfully exfiltrated internal files. No additional technical details about the initial access vector, exact data categories, or volume of records appear in the posting. The notification does not quantify how many customers, employees, or partner organizations may have had information contained in the stolen files. Public reporting on the incident remains limited to the leak-site entry itself, which serves as the authoritative primary source.
Why This Matters for You and Your Family
When a company that builds core record-keeping systems for notaries and legal offices is breached, the exposure can reach far beyond corporate walls. Notaries handle wills, property deeds, marriage records, and business filings that frequently include your full name, address, tax identification numbers, signatures, and family details. If any of those documents or related databases were stored in Escriba’s systems, your personal information may now sit in an attacker’s archive. Even without an exact victim count, the high severity rating reflects the sensitivity of the sector Escriba serves. Families across Brazil who have used notarial services in recent years should treat this incident as relevant to them.
Doxxing and Identity-Chain Risks
Stolen internal files from a software provider to the notary industry often contain spreadsheets, configuration files, support tickets, or integration logs that link names, emails, phone numbers, and government identifiers. Attackers can combine these fragments with data from earlier breaches to build complete identity profiles. A single leaked notary record can expose relationships between parents, children, and spouses, making it easier for criminals to launch targeted phishing, account takeovers, or impersonation schemes. Credential leaks of this nature frequently cascade into gaming accounts belonging to you or your children, where the same email and password combinations are reused. Once a gaming handle is hijacked, it can be used to harvest further personal details or to pressure families through doxxing.