CSIDB logo
Incident

Tribunal de Justiça do Distrito Federal e dos Territórios

Incident posture

Attack window
Jul 2022
Location
Brazil
Status
Historical
CIA posture
Available to members
Updated
2025-10-17 00:00

Linked entities

Victim
Tribunal de Justiça do Distrito Federal e dos Territórios
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jul 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Tribunal de Justiça do Distrito Federal e dos Territórios experienced a cyber incident resulting in its website being offline for four days before returning with ongoing instability due to technical adjustments. The Civil Police initiated an investigation into the alleged hackers responsible for disrupting the platform. No ransomware group claimed responsibility for the attack, and no evidence emerged of stolen data being offered for sale or public download. The organization's systems remained under scrutiny as authorities worked to determine the scope and nature of the intrusion.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Tribunal de Justiça do Distrito Federal e dos Territórios (TJDFT) experienced a disruptive cyber incident beginning on or around July 30, 2022, which forced its website offline for four consecutive days. The platform remained completely inaccessible during this period, disrupting public access to judicial services and information. Technical teams worked to restore functionality, with the website returning online by August 3, though operational stability was not fully achieved. Users reported persistent instability due to ongoing adjustments implemented by TJDFT’s IT personnel. The Civil Police of the Distrito Federal initiated a formal investigation to identify the perpetrators responsible for the attack, though no specific threat actor group or individual was publicly named at this stage.

Authorities did not disclose technical details regarding the attack vector, compromised systems, or data exfiltration. Cybersecurity monitoring groups, including DataBreaches.net, found no evidence of ransomware groups claiming responsibility for the TJDFT intrusion through their typical communication channels. No datasets allegedly stolen from TJDFT appeared on dark web markets or leak sites during or after the outage. The incident’s primary observable impact was the prolonged unavailability of the court’s digital platform, followed by intermittent accessibility issues during recovery efforts. TJDFT’s public communications emphasized restoration work and police involvement but did not quantify operational or financial consequences stemming from the disruption.

Sources

Sources available to members: 1 source.

CSIDB