Cyber Incident Victim: Palmas, Tocantins, Brazil
Date:
Jan 2023
Location:
Brazil
Summary
Government websites in Tocantins, Brazil, experienced a cyberattack involving unauthorized defacement, with hackers altering content to display manipulated images of the country's president. The state's IT Agency took affected portals offline as a precautionary measure and initiated restoration efforts, though services remained unavailable the following day with a public error message acknowledging the disruption. Authorities activated the specialized cybercrime division of the Civil Police to investigate the incident's origin and identify perpetrators. The attack caused temporary operational impacts but did not involve reported data loss, mirroring recent targeting patterns against Brazilian public sector entities.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On the evening of January 17, 2023, government websites in Tocantins, Brazil, experienced a cyberattack that compromised multiple platforms operated by state secretariats. At approximately 8:00 PM local time, attackers breached the systems and defaced websites by publishing images of President Luiz Inácio Lula da Silva, including a digitally altered photograph depicting him in a prison setting. The Agência de Tecnologia da Informação (ATI), responsible for managing the state's digital infrastructure, confirmed the incident and implemented immediate containment measures by taking all affected portals offline as a precautionary step. By the morning of January 18, the websites remained inaccessible, displaying a standardized error message indicating technical difficulties and ongoing restoration efforts. The ATI publicly stated that hackers had modified content on some pages and emphasized their focus on restoring services securely while guarding against potential follow-up attacks.

The Tocantins Civil Police initiated an investigation through its specialized cybercrime unit (DRCC) to trace the attack's origin and identify perpetrators. No data loss or additional attacker objectives beyond the defacement were disclosed in official communications. Service disruptions persisted into the following day, with no specified restoration timeline provided by authorities. The ATI's full statement reiterated the precautionary takedown of portals and collaboration with law enforcement. This incident occurred amid a broader pattern of cyberattacks targeting Brazilian public sector entities in early 2023, though the narrative specifically concerning Tocantins contains no confirmed technical details about attack vectors, infrastructure impacts beyond website unavailability, or attribution beyond generic references to "hackers." Restoration efforts prioritized security reinforcement against potential subsequent incidents.
