Alicotrans Ransomware Claim by Qilin - Sept 2026
Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.
Leak Site Screenshot
Screenshot captured at time of discovery. Image blurred to protect victim PII.
Claim Summary
On or around September 14, 2026, the ransomware group tracked as qilin allegedly listed Alicotrans, a Brazilian transportation and logistics company operating at www.alicotrans.com, on its dark web leak site. According to the threat actor’s post, the victim was added on September 14, 2026, with the country of operation listed as Brazil (BR) and the industry classified as transportation.
Notably, the group has not published a data volume figure, a sample set, or a countdown timer in the information available to us. The “Claimed Data” field is marked as not available, and the data volume is listed as undisclosed. This is an important caveat: a listing without supporting evidence is a claim, not a confirmed breach.
Yazoul Security has NOT independently verified this claim. It remains unconfirmed at the time of writing.
Threat Actor Profile
Qilin (also tracked by some vendors under alternate names) is a ransomware-as-a-service (RaaS) operation that has been active since roughly 2022. The group is generally associated with double extortion tactics, meaning it purports to both encrypt victim systems and exfiltrate data for leverage. Public reporting has linked Qilin to a broad range of victims across healthcare, manufacturing, education, and professional services, with a notable concentration in North America and Europe. This alleged Brazilian transportation victim would be consistent with the group’s broad, opportunistic targeting.
Regarding tooling: no specific tools, malware families, or tactics are confirmed in the data provided for this claim, and no public research references were supplied. Based on widely reported industry observations, Qilin affiliates have historically relied on a mix of initial access via phishing, valid credentials, and exploitation of exposed remote services, followed by common living-off-the-land utilities and commercial or commodity tooling. We cannot confirm which, if any, of these were used against Alicotrans.
No YARA rules or detection signatures specific to this claim are available to us. Organizations should rely on their existing endpoint detection and response (EDR) coverage, network monitoring, and threat hunting programs rather than any claim-specific indicator.
Alleged Data Exposure
The threat actor has not, according to the available listing, disclosed the volume or nature of any allegedly stolen data. No samples, file trees, or proof-of-compromise artifacts have been referenced in the information we reviewed.
This absence is significant. Ransomware groups frequently publish partial proof to pressure victims into paying. A listing with no evidence may indicate: (a) negotiations are ongoing and the group is withholding proof as leverage, (b) the group is exaggerating or bluffing, or (c) the listing is incomplete or recently posted. We cannot determine which scenario applies.
Potential Impact
If the claim is accurate, a transportation and logistics operator could face operational disruption to fleet, dispatch, or supply chain systems, plus potential regulatory exposure under Brazilian data protection law (LGPD) if personal data was involved. Transportation firms also hold customer, partner, and employee records that could be monetized or used in follow-on fraud.
However, because no data volume or sample has been provided, the actual scope of any exposure is unknown. We caution against assuming the worst-case scenario based solely on a leak site post.
What to Watch For
- Whether Qilin publishes proof-of-compromise artifacts or a data volume in the coming days.
- Any official statement from Alicotrans or its parent/partner organizations.
- Brazilian media or CERT.br advisories referencing the incident.
- Follow-on phishing or fraud campaigns referencing Alicotrans customer data.
- Whether the listing is removed, suggesting a settlement, or escalated.
Disclaimer
This report is based entirely on an unverified claim published by a ransomware group on its leak site. Yazoul Security has NOT independently confirmed that Alicotrans was breached, that any data was exfiltrated, or that the threat actor’s statements are accurate. Ransomware groups routinely exaggerate, misattribute, or fabricate claims to pressure victims and generate publicity. Nothing in this report should be treated as established fact. Affected parties should conduct their own forensic investigation and consult legal counsel. For related coverage, see our /news/ section.
Never miss a threat intelligence alert
Get real-time security alerts delivered to your preferred platform.
Related Claims
CARIDRO VAL DE LOIRE — qilin
Opera Comique — qilin
Kinetic Education — qilin
Majlis Perbandaran Alor Gajah — qilin