FUNAP Ransomware Claim by Booba Project (Oct 2026)
Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.
Claim Summary
The Booba Project ransomware group has allegedly listed FUNAP - Fundação “Prof. Dr. Manoel Pedro Pimentel” on its dark web leak site. According to the threat actor, the organization was added on October 1, 2026, and approximately 26 GB of data was purportedly exfiltrated. The group describes the stolen material as “Government Relations Services” data.
FUNAP is a Brazilian foundation linked to the São Paulo state prison system, providing work and reintegration programs for incarcerated individuals. Its domain, funap.sp.gov.br, places it within Brazil’s public sector, which falls under the Government & Defense industry category.
This claim has NOT been independently verified by Yazoul Security or any third party. It remains a single unconfirmed assertion published by a criminal actor.
Threat Actor Profile
The claim is attributed to Booba Project, a ransomware operation with limited public visibility. At the time of writing, there is no public research available on this group, and its total number of known victims is unknown. No established toolset, malware family, or tactical playbook has been publicly documented for Booba Project.
Because so little is known, the group’s credibility cannot be reliably assessed. Newer or rebranded ransomware operations frequently make aggressive claims to build notoriety, and some leak site entries are recycled, exaggerated, or entirely fabricated. Analysts should treat this listing with heightened skepticism until corroborating evidence emerges.
No YARA rules or detection signatures specific to Booba Project are currently available. Organizations should rely on general ransomware detection guidance, including monitoring for unusual data staging, large outbound transfers, and unauthorized access to backup infrastructure.
Alleged Data Exposure
The group claims to have stolen 26 GB of data, described only as “Government Relations Services” material. No data samples, file listings, or proof-of-compromise artifacts have been referenced in this report, and none should be sought or shared.
If the claim is accurate, the exposed material could potentially include internal communications, administrative records, or service-related documentation. However, the vague description provides no basis to confirm the nature, sensitivity, or authenticity of any alleged data. Ransomware groups routinely mislabel or inflate the contents of their leaks.
Potential Impact
For a public foundation tied to a state prison system, even an unverified data theft claim carries reputational and operational risk. Potential consequences could include:
- Public trust erosion if sensitive records are later confirmed to be exposed.
- Regulatory scrutiny under Brazilian data protection law (LGPD), depending on the data categories involved.
- Disruption to reintegration programs and partner relationships if systems were affected.
- Secondary targeting, including phishing or fraud, if personal data is eventually leaked.
It is important to note that none of these outcomes are confirmed. The claim alone does not establish that a breach occurred.
What to Watch For
- Official statements from FUNAP or São Paulo state authorities confirming or denying an incident.
- Independent corroboration from Brazilian CERT or government cybersecurity channels.
- Publication of data samples by the group, which would raise confidence in the claim.
- Additional victims listed by Booba Project, which could indicate an active campaign.
- Any signs of credential abuse or follow-on phishing referencing FUNAP.
Yazoul Security will continue monitoring this claim and will update our coverage if verified information becomes available. For related reporting, see our /news/ section.
Disclaimer
This report is based solely on an unverified claim published by a ransomware group on its leak site. Yazoul Security has NOT independently confirmed that a breach occurred, that any data was stolen, or that the listed organization was actually compromised. Ransomware actors frequently exaggerate, misrepresent, or fabricate claims to pressure victims and generate publicity. Nothing in this article should be treated as established fact. No personal data, credentials, download links, or access instructions are included, and none should be pursued.
Never miss a threat intelligence alert
Get real-time security alerts delivered to your preferred platform.
Related Claims
The Merrimack County — Booba Project
Washington County — Booba Project
University of Illinois Chicago — Booba Project
Smart Eye Care — Booba Project