On June 2, 2026, Brazilian debt collection firm SICOL appeared on the leak site of the spacebears ransomware group. The company, formally known as JS Cobranças e Serviços, handles credit management and sales services for businesses across Brazil. Public reporting indicates that internal files containing personal information of employees and clients, financial documents, and other sensitive records were exfiltrated during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Sicol
Get alerted the next time Sicol files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Sicol’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes SICOL as a company that combines digital automation with personal customer support to recover debts and improve sales workflows. The data set listed on the spacebears leak site includes employee and client personal information along with financial records. No exact victim count has been publicly confirmed, and the precise volume of exposed files remains unclear. The incident follows the group’s typical pattern of stealing data before encrypting systems and later publishing samples as leverage for payment.
Why This Matters for You and Your Family
When a debt collection company loses control of client and employee records, the fallout can reach ordinary people like you. Personal information and financial documents in the wrong hands can lead to identity theft, fraudulent loans taken out in your name, or harassing collection attempts on debts that are not yours. If you or any member of your family has ever done business with a Brazilian credit or collections firm, your details could be among those now circulating. Children’s records, sometimes included in family-linked accounts, are especially vulnerable because they lack credit history and can be exploited for years before detection.
The Doxxing and Identity-Chain Risks
Leaked personal records rarely stay isolated. A single email address, phone number, or client ID from this claimed breach can be cross-referenced with information from previous leaks to build a complete profile. Attackers chain these fragments together to locate social media accounts, gaming usernames, home addresses, and family relationships. Once the chain is mapped, it becomes easier to hijack accounts, send targeted phishing messages, or publish personal details online for harassment. Credential leaks of this nature frequently cascade into gaming account takeovers, where children’s profiles are seized and used to demand ransom from parents or to spread malware to their friends.