CSIDB logo
Incident

Tribunal Federal da 3ª Região

Incident posture

Attack window
Mar 2025
Location
Brazil
Status
Unknown
CIA posture
Available to members
Updated
2026-03-24 04:54

Linked entities

Victim
Tribunal Federal da 3ª Região
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Tribunal Regional Federalda 3ª Região reported that its electronic, judicial and administrative systems became unstable after a distributed denial‑of‑service attack overwhelmed its servers and blocked legitimate access to online services. The attack was quickly mitigated, normal operation was restored, and the tribunal confirmed that no data were lost, compromised or exposed during the incident. As a precaution, filing deadlines for legal documents were extended while services were being stabilized.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Friday, March 7, 2025, the electronic, judicial and administrative systems of the Federal Justice of the Third Region (TRF‑3) experienced a period of instability. The TRF‑3 of São Paulo issued a confirmation that the disruption was caused by a Distributed Denial of Service (DDoS) attack targeting its web portals. According to the official statement, the attacker’s activity overloaded the servers, which prevented legitimate users from accessing the services provided by the tribunal. The overload persisted for a portion of the day, affecting the availability of online judicial and administrative functions.

In response to the attack, TRF‑3 reported that all malicious traffic was promptly mitigated and that its systems have been restored to normal operation. The tribunal emphasized that no data was lost, compromised or exposed during the incident. As a consequence of the service interruption, TRF‑3 announced that it would extend the deadlines for the submission of documents by the parties involved in legal proceedings (PJs). The extension was intended to accommodate users who were unable to access the portal while the DDoS attack was ongoing.

The official communication released by TRF‑3, disseminated through Security Report, detailed that the instability observed on March 7 was directly attributable to the DDoS attack, which aimed to overload servers and block legitimate access. It reiterated that the mitigation efforts were successful, the systems are functioning normally, and the tribunal remains committed to maintaining the integrity and availability of its electronic services. The statement closed by reinforcing that the incident did not result in any data breach or loss.

Sources

Sources available to members: 1 source.

CSIDB