On October 2, 2024, Brazilian ERP provider FoccoERP appeared on the leak site of the trinity Ransomware Group. The listing, which became active on the group’s onion portal and was indexed via ransomware.live, states that the company suffered a ransomware attack resulting in the exfiltration of internal files. The threat actors claim to hold a 300 GB database belonging to a firm with roughly $20 million in annual revenue. Publication of the stolen data was scheduled for November 1, 2024. The exact number of individuals whose records were taken remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch FoccoERP
Get alerted the next time FoccoERP files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about FoccoERP’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The trinity leak-site entry states that FoccoERP was compromised through a ransomware operation. It lists the victim’s name, revenue range, and the volume of data allegedly obtained but does not specify the precise file types or categories of personal information inside the 300 GB archive. The disclosure indicates the data was exfiltrated prior to encryption and is now held for extortion. No ransom amount or negotiation status is published on the listing itself. Public mirrors of the onion page, such as the one hosted on ransomware.live, preserve these claims exactly as posted by the operators.
Why This Matters for You and Your Family
When a company that supplies enterprise resource planning software is breached, the ripple effects reach far beyond its own walls. FoccoERP’s customers include mid-sized businesses whose payroll, customer invoices, supplier contracts, and employee tax documents may have been stored inside the compromised systems. If your employer, your child’s school, your medical provider, or any vendor you deal with uses FoccoERP, your personal or household data could be among the records now in criminal hands. The 300 GB volume suggests a large and varied dataset even though the exact number of affected people is not stated.
Doxxing and Identity-Chain Risks
Internal files from an ERP platform frequently contain spreadsheets that link names, national identification numbers, addresses, bank details, and email addresses. Once such data reaches a ransomware leak site, it is routinely repackaged and sold on underground forums. Threat actors then combine it with credential leaks from other breaches to build detailed identity chains. A single exposed work email can lead to your personal accounts, your children’s gaming profiles, and ultimately to physical addresses and family relationships. These chains accelerate doxxing, targeted phishing, and account takeovers that can affect every member of a household.