2026 Correios (Brazil) — internal documents / operational scans leak claims (Apr)
Data compromised
Operational, employee, and customer shipment metadata per OSINT—scope varies
Technical writeup
In mid–April 2026, dark-web monitoring accounts and secondary trackers (Dark Web Informer, security news summaries) described a dataset allegedly tied to Brazil’s national postal operator (Correios / ECT), including narratives about thousands of internal scans, mailing receipts linked to major banks, employee identifiers, and sorting-center architectural materials. Actor branding varied across posts (e.g., CoinbaseCartel vs. other personas in different mirrors). Treat quantitative impact as unsettled pending Correios acknowledgment.
Root cause
Unauthorized internal document exposure / forum resale (details evolving)