On December 09, 2024, the Brazilian cashback platform melhorcompraclube.com.br appeared on the leak site operated by the ransomware group known as apt73. The listing states that the company, originally a product of Telepequisa, suffered a ransomware attack in which internal files were exfiltrated. The number of people whose data was taken remains unknown, and the leak-site listing does not detail the specific types of records involved beyond claiming that internal files were stolen.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch melhorcompraclube.com.br
Get alerted the next time melhorcompraclube.com.br files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about melhorcompraclube.com.br’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The apt73 leak page explicitly lists melhorcompraclube.com.br as a victim and asserts that data was obtained during a ransomware operation. It describes the company as a cashback platform with roots in Telepequisa, a firm with nearly 30 years of market research experience in Brazil. The disclosure indicates that files were exfiltrated but provides no count of affected records, no sample documents, and no deadline for ransom payment. Public mirrors of the listing, such as the one hosted on ransomware.live, preserve these limited claims without additional elaboration from the threat actor.
Why This Matters for You and Your Family
When a cashback and loyalty platform is breached, the information exposed often includes personal details tied to everyday spending, rewards accounts, and contact records. If your email, phone number, or purchase history appears in the stolen files, criminals can use it to craft convincing phishing messages that look like legitimate cashback offers or account alerts. Internal files exfiltrated in such attacks frequently contain spreadsheets or databases that link names, addresses, and transaction patterns, increasing the chance that you or members of your household could face targeted fraud attempts months after the initial breach.
Even when exact record counts are not published, the real-world impact is personal. Families who used the platform to earn cash back on routine purchases may now find their data circulating among criminals who buy and sell stolen information on underground forums.