Menu
Browse

Cyber Incident Victim: Rede Bahia

Date:

May 2021

Location:

Brazil

Summary

A Brazilian multimedia conglomerate experienced a ransomware attack that disrupted operations, particularly affecting its newspaper's daily publication and prompting temporary reliance on alternative news distribution channels. The organization implemented technical measures and engaged specialized firms to mitigate risks while investigating leaked employee and former employee data, including salary information shared via email and social media platforms. Internal communications acknowledged the breach and authorities were notified, though specifics regarding the ransomware variant or any ransom demands remained undisclosed at the time of reporting.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On May 13, 2021, Rede Bahia, a Brazilian multimedia conglomerate operating 16 outlets focused on Bahia, experienced a ransomware attack that disrupted its operations. The attack compromised the organization’s servers and systems, impairing critical functions, including the daily publication of its newspaper, Correio. Rede Bahia issued an internal memo the same day, informing employees of the breach and confirming the unauthorized access had affected employee and former employee data. The company stated it had implemented technical and security measures to contain the incident, including engaging specialized firms to mitigate risks. Operations remained partially disrupted at the time of reporting, with restoration efforts ongoing.

Cyber Incident Image

The attack led to the public disclosure of sensitive employee information, though the full scope of exposed data was not detailed. BNEWS, a subsidiary, initially reported and later removed a screenshot purportedly showing redacted employee salary information circulated via email and social media; its authenticity remained unverified. Rede Bahia publicly directed audiences to alternative news platforms like radio and online channels during service interruptions. The organization acknowledged involving unspecified authorities to investigate the incident and determine responsibilities. No ransomware variant, ransom demands, or explicit attribution were disclosed. The incident highlighted operational vulnerabilities and data protection challenges, with employee privacy impacts confirmed but not quantified. Rede Bahia’s response prioritized internal communication, external partnerships for recovery, and regulatory compliance, though system restoration timelines were unresolved when reported.

Sources
Sources available to members
1 source