On November 26, 2024, the Brazilian engineering and consulting firm www.sella.eng.br appeared on the leak site operated by the ransomware group known as apt73. The listing states that internal files were exfiltrated during a ransomware attack and are now publicly available for download, totaling 0.3 GB of material described as mentoring programs for managers along with other internal and personal documents. The number of people whose information is contained in the files remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch sella.eng.br
Get alerted the next time sella.eng.br files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about sella.eng.br’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The apt73 leak page explicitly lists Sella as a victim and confirms the data was taken in a ransomware incident. It does not specify the exact systems breached, the precise number of records affected, or name every document type beyond the categories of internal files, mentoring materials, and personal documents. The disclosure indicates the information is now hosted on their onion site and available to anyone who visits. No ransom demand figure or negotiation status is published on the page.
Why This Matters for You and Your Family
When a company that provides engineering or consulting services is hit, the documents it holds often contain information about clients, employees, contractors, or partners. If your name, address, national ID, email, phone number, or financial details appear in those mentoring files or related personal documents, the exposure is permanent. Once data leaves a corporate network and reaches a ransomware leak site, it can be indexed, sold, or used in follow-on attacks for years. For ordinary families this means heightened risk of identity theft, targeted phishing, or unwanted contact tied directly to your real-world identity.
The Doxxing and Identity-Chain Risk
Internal documents frequently link work email addresses to personal phone numbers, home addresses, or even family member names. Attackers chain these fragments together: an email from the breach can be tested against gaming accounts, social-media handles, or online shopping profiles. The result is a detailed profile that reveals where you live, where your children go to school, or which accounts control your household finances. Credential leaks of this nature regularly cascade into account takeovers, especially for gaming platforms used by children that often share the same passwords or recovery emails as adult accounts.