L0RDBR
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
L0RDBR, also known by the alias JustBR, is a threat actor identified as operating from Brazil. The actor came to public attention during Operation Deepwater, a Federal Police action that took place on January 1 2021, when Marcos Roberto Correia da Silva, who used the alias “Vanda the God,” was arrested for allegedly orchestrating Brazil’s largest data breach. In that incident, a second individual using the alias JustBR reportedly offered the stolen data for sale on the cybercrime forum RaidForums, prompting additional investigative warrants. The compromised information included Individual Taxpayer Registry (CPF) numbers, Corporate Taxpayer Registry (CNPJ) details, full names, and addresses of roughly 223 million individuals, affecting both private citizens and government authorities.
A separate report published on March 9 2021 noted that China’s Cosco Shipping was allegedly hacked by LORDBR, although the article explicitly labeled this claim as unconfirmed and under investigation at the time of publication. The same article also described unrelated ransomware incidents affecting a French hospital and Spain’s public employment service, but no connection was made between those events and LORDBR or JustBR. No specific malware families, initial‑access vectors, or tooling details are described in the available sources for either the data‑breach operation or the alleged Cosco Shipping incident; the only observable activity involves the illicit acquisition and subsequent commercialization of personal and corporate records.
The demonstrated activity of LORDBR/JustBR appears to be financially motivated, centered on the theft and sale of large datasets, with no publicly asserted ties to state sponsors, espionage goals, or disruptive objectives. Aside from the Operation Deepwater breach and the unverified Cosco Shipping allegation, no other campaigns or operational patterns have been documented in open‑source reporting. Consequently, the profile remains limited to the confirmed facts of the Brazilian data‑breach involvement and the unconfirmed shipping‑sector allegation, without further extrapolation about the actor’s broader capabilities or affiliations.
Incidents
Attributed incidents are available to members.
2 incidents