Everest ransomware group claimed responsibility for breaching Petrobras, Brazil's state-owned oil and gas giant, and exfiltrating over 90 GB of sensitive seismic navigation data. The stolen files reportedly include detailed technical information such as ship positioning, equipment configurations, hydrophone readings, depth measurements, and quality control documents related to Petrobras' seismic surveys, particularly in the Campos Basin. Screenshots of the stolen data were published by the threat actors to substantiate their claims, and the data is said to include both 3D and 4D survey datasets, which are critical for oil exploration and production.
The breach poses a significant reputational risk to Petrobras and could undermine its competitive advantage, as the exposed data may allow competitors to replicate Petrobras' methods or gain leverage in contract negotiations. While the data does not appear to include real-time corporate access, the leak of such proprietary research and technical documentation could have long-term strategic implications for Petrobras. Everest's claims follow a pattern of targeting major industrial and energy sector organizations worldwide.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
After claiming the intrusion, Everest said it would release the allegedly stolen Petrobras data in less than a week. Reported impacts centered on reputational harm and possible competitive disadvantage from exposure of ship positioning and equipment usage details.
The Everest ransomware operation allegedly compromised Petrobras and claimed to have exfiltrated about 90 GB of data. The group said the stolen material included sensitive geophysical and navigation-related information related to Petrobras' Campos Basin post-salt research.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.