2025 Petrobras — Everest leak-site claims vs seismic/exploration datasets; Petrobras cites third-party contractor scope (Nov)
Data compromised
If genuine, high-sensitivity subsurface survey intelligence rather than retail consumer PII
Technical writeup
In mid-November 2025, the Everest extortion brand listed Petróleo Brasileiro S.A. (Petrobras) on its leak portal, alleging theft of ~90 GB of Campos Basin 3D/4D seismic survey metadata spanning ship tracks, hydrophone geometry, QC PDFs, and equipment configs. Cybernews quoted Petrobras asserting no direct compromise of corporate crown-jewel networks and framing the episode as an isolated incident at an exploration vendor processing survey data. Admin By Request’s incident recap collated the postings’ timelines while cautioning that intrusion dates upstream of the leak listing remain opaque—treat field-level record counts as unpublished.
Root cause
Ransomware/extortion operator campaign—likely initial access via contractor ecosystem (details not certifiable from Petrobras open correspondence alone)