Menu
Browse

Cyber Incident Victim: Salvador, Bahai, Brazil

Date:

Jan 2022

Location:

Brazil

Summary

A cyberattack defaced approximately 20 government websites hosted by the state data processing company Prodeb, attributed to a group using the "Shawdy Boy" signature previously linked to an incident impacting 245 municipal sites in Santa Catarina. The attackers demonstrated privileged server access through defacement screens, though Prodeb confirmed no internal structural alterations, data breaches, or deletions occurred. Affected agencies included security, civil police, and infrastructure departments, with services temporarily disrupted before gradual restoration. The same group claimed responsibility for additional defacements targeting Piauí government domains via Zone-H, while Bahia's Security Secretariat launched an investigation involving civil police and intelligence units.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
2 actors Available to members Available to members

Description

On January 20, 2022, a cyberattack targeted 20 websites belonging to the government of Bahia, Brazil, hosted by the state's data processing company Prodeb. The attackers defaced the sites, displaying a signature identifying themselves as "Shawdy Boy" – the same alias used in a December 2021 attack that disrupted 245 municipal websites in Santa Catarina state. Affected entities included critical state secretariats: Public Security, Civil Police, Administration, Equality, Infrastructure, Justice and Human Rights, and the Civil Office. Prodeb did not issue an official statement but confirmed to media that the attack didn't alter internal website structures or compromise public data through access, leaks, or deletion. Forensic evidence from defacement screens (revealed through the 'uname' command) indicated attackers obtained privileged server access. The government temporarily deactivated all compromised sites, initiating gradual restoration throughout the day.

Cyber Incident Image

Bahia's Public Security Secretariat (SSP) launched an investigation through the Civil Police with support from the Superintendency of Intelligence. The attackers registered their defacements on Zone-H, a platform documenting website vandalism, and also claimed responsibility for targeting government domains in Piauí state. This group previously operated as "$hawty Boy" during the Santa Catarina incident, maintaining connections to a Twitter account "@PrCyberMafia" (Paraná Cyber Mafia). While Prodeb asserted no data exfiltration occurred, the repeated use of attacker infrastructure across multiple states demonstrated persistent targeting of Brazilian government entities. Restoration efforts prioritized returning sites to operational status without public disclosure of technical remediation measures or attribution conclusions.

Sources
Sources available to members
1 source