CSIDB logo
Incident

Ministry of Mines and Energy of Brazil

Incident posture

Attack window
Oct 2025
Location
Brazil
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 18:20

Linked entities

Victim
Ministry of Mines and Energy of Brazil
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2025
Discovered
Undetermined
Disclosed
Feb 2026
Resolved
Pending

Summary

An Asian state‑aligned cyber‑espionage group compromised the networks of about seventy organisations in more than thirty‑seven countries, including the Ministry of Mines and Energy of Brazil, by using tailored phishing emails and exploiting unpatched software vulnerabilities. The attackers gained access to email servers, exfiltrated sensitive information, and monitored communications related to financial, diplomatic, military and police matters while remaining undetected for months. Palo Alto Networks identified the intrusion, notified the affected entities and offered assistance, and the US Cybersecurity and Infrastructure Security Agency said it is working with partners to address the exploited vulnerabilities.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The cyber‑espionage group described by Palo Alto Networks conducted a year‑long campaign that breached government and critical‑infrastructure networks in over 37 countries. The group’s tactics included highly‑targeted spear‑phishing emails and exploitation of known, unpatched security flaws to gain initial access. Among the victims identified in the report was the Ministry of Mines and Energy of Brazil, which the report notes is a major supply base of rare earth mineral reserves. The compromise of the ministry’s networks was part of the broader set of intrusions that also hit law‑enforcement agencies, finance ministries, a parliament and a senior elected official.

Once inside, the attackers used the access to monitor email traffic, financial dealings and communications related to military and police operations, as well as diplomatic matters. They exfiltrated sensitive data from the ministry’s email servers and remained undetected within the system for months, consistent with their behavior in other compromised networks. The report states that the group lurked in some victims’ systems for extended periods, gathering information that coincided with geopolitical events such as diplomatic meetings and trade negotiations. No public indication of detection by the ministry’s internal security teams emerged during the intrusion period.

In October, while US diplomats were holding meetings with Brazilian mining executives, an official at the Ministry of Mines and Energy told reporters that the ministry had not identified any attack on its systems. Palo Alto Networks said it had notified the affected victims, including the ministry, and offered assistance after confirming the data exfiltration. The firm also named some of the victims in its published report, an atypical step for a cyber‑security company, thereby providing limited public acknowledgment of the Brazil ministry’s involvement.

Sources

Sources available to members: 1 source.

CSIDB