A major cyber intrusion that paralyzed nine Brazilian federal ministries in late July has been linked to a previously unknown ransomware operation dubbed “Fog,” according to investigative findings and law enforcement records.
The attack, which also compromised Brazil’s national mint and its anti-money laundering agency, saw hackers exfiltrate at least 28 gigabytes of sensitive government data to servers located in the United States. The perpetrators demanded $1.2 million to restore encrypted systems.
Following the breach, Brazilian authorities formally requested assistance from U.S. law enforcement to access data stored on four virtual machines believed to be connected to the attack’s origin. This triggered a joint investigation between the two nations.
The cybercriminals gained entry by compromising credentials for Virtual Private Networks provided by four American companies, a tactic commonly used to mask their true locations. Investigators have since requested data preservation from three of these providers, while efforts to contact the fourth remain pending.
Records show the group known as Fog has claimed responsibility for 58 separate attacks between June and November, with over 70% targeting U.S.-based institutions. Victims span a dozen countries, including Australia, Germany, and Canada.
A ransom note left for Brazilian officials stated: “If you are reading this, then you have been the victim of a cyberattack. We call ourselves Fog and take full responsibility for this incident.” The note directed negotiators to a private chat, where the attackers provided a list of 1,087 compromised files totaling roughly 29 gigabytes.
Among the stolen documents were files referencing Dataprev, the agency handling social security data, and Siconv, which manages federal transfer agreements. File names such as “usuarios_conc_siconv.qvd” and “dados_bancarios_cultura_LPG.qvd” suggest the theft included personal identifiers and banking information.
Cybersecurity firm Arctic Wolf, which first identified the Fog ransomware variant in June, noted that the emergence of a named criminal group signals an evolution from isolated attacks to organized criminal enterprises.
Brazil currently relies on extortion laws dating to 1940 to prosecute such crimes, though lawmakers are considering updates. Senator Carlos Viana, leading one legislative proposal, described the existing framework as “treating extortion crimes with the same parameters of the 20th century.” A separate proposal by Senator Angelo Coronel seeks to create a specific legal category for digital extortion.
The data preservation request was processed through the 24/7 Network of the Organization of American States, which facilitates cross-border cybercrime investigations. However, legal experts note that preserving data with foreign companies presents challenges due to jurisdictional differences and sovereignty concerns.
Authorities have not confirmed whether any ransom payment was made, and communications between officials and the group show no evidence of funds being transferred. The Brazilian Federal Police declined to comment on the ongoing investigation.