CSIDB logo
Incident

Secretaria de Saúde de São Jerônimo

Incident posture

Attack window
Apr 2025
Location
Brazil
Status
Unknown
CIA posture
Available to members
Updated
2026-03-21 02:18

Linked entities

Victim
Secretaria de Saúde de São Jerônimo
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Secretariade Saúde de São Jerônimo reported that its WhatsApp ambulance request line was targeted in a recent hacking attempt, prompting the temporary suspension of the service before it was restored and confirmed to be fully operational. The municipality’s official statement noted that the number 51 99692-1212 had been reestablished and apologized for any inconvenience caused to residents seeking emergency medical transport. In a separate incident, another municipal administration disclosed a cyber breach that exposed data from several of its secretariats, though details of that event were not linked to the health department’s case.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On the weekend ofMarch 29‑30 2025, the Municipal Health Secretariat of São Jerônimo in Rio Grande do Sul reported that it had suffered a hacker attempt targeting its WhatsApp ambulance call service. The specific WhatsApp number identified as at risk was 51 99692‑1212, which the secretariat uses to receive requests for ambulance dispatch. According to the official statement released by the secretariat, the number had been compromised during the attack but was subsequently restored and is now fully functional. The secretariat apologized for any inconvenience caused and confirmed that ambulance attendance services are available 24 hours a day.

In a separate incident disclosed by the article, the Prefecture of Taubaté in São Paulo admitted in an official note published on its website that it had experienced a cyber incident in August 2024 resulting in a data leak. The note stated that an threat actor had invaded the servers of the local administration, gaining access to information stored across multiple municipal secretariats. The data exposed included records held by the Secretariats of Health, Education, Administration, General Prosecutor’s Office, Planning, Housing, Finance and Government. The prefecture’s communication did not provide further technical details about the breach or the data volume involved.

The impacts of the São Jerônimo event were limited to a temporary disruption of the WhatsApp‑based ambulance call channel, which was resolved once the number was reestablished, allowing the secretariat to resume normal operations and continue providing emergency medical transport. In Taubaté, the confirmed data leak affected the Health Secretariat alongside seven other municipal departments, potentially exposing personal and administrative information managed by those offices. The response actions described in the sources consisted of the secretariat’s public apology and service restoration notice in São Jerônimo and the prefecture’s public acknowledgment of the incident and disclosure of the affected secretariats in Taubaté.

Sources

Sources available to members: 1 source.

CSIDB