On January 18, 2024, the Brazilian federal university UFFS.edu.br appeared on the leak site operated by the ransomware group Stormous. The listing states that internal files were exfiltrated during a ransomware attack. The university, which serves students and staff across Santa Catarina, Paraná, and Rio Grande do Sul, has not publicly quantified how many individuals may be affected, and the leak-site listing does not detail the exact volume or specific categories of data taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch uffs.edu.br
Get alerted the next time uffs.edu.br files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about uffs.edu.br’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The Stormous leak page, still accessible via the onion link at the time of analysis, claims successful data theft from the public federal university. It presents samples of the allegedly stolen material and threatens further publication if demands are not met. The disclosure indicates that the files are internal documents obtained after the group gained access to UFFS systems. No precise record count is provided, and the university itself has not issued a detailed public notification specifying which databases or servers were compromised. Public reporting on similar Stormous listings shows the group typically posts compressed archives or directory listings as proof of exfiltration.
Why This Matters for You and Your Family
If you, your children, or any household member attended or worked at UFFS, your personal information may now sit in an attacker-controlled archive. Internal files from a university environment commonly contain names, dates of birth, national identification numbers, addresses, academic records, and contact details for students, alumni, faculty, and administrative staff. Even without an exact victim count, the exposure creates immediate risk because universities hold data on entire families—parents listed as emergency contacts, siblings in shared enrollment records, and dependents in scholarship files. Once such information leaves institutional control, it circulates among cybercriminals who combine it with other leaks to build detailed profiles.
Doxxing and Identity-Chain Implications
A single university breach rarely stays isolated. The exposed internal files can link email addresses, phone numbers, and government IDs to usernames used on social media, gaming platforms, and shopping sites. Attackers then follow these chains to locate family members, map household addresses, and target children’s accounts. Credential leaks of this nature frequently cascade into gaming-platform takeovers, where stolen university email passwords are tested against Steam, Roblox, or Discord logins. The result is doxxing that reaches beyond the original victim to expose minors whose gaming handles and chat logs become public. Continuous monitoring across large breach repositories is essential because these identity chains grow over months as new correlated data appears on underground forums.