Ransomware

Brain Cipher Claims Responsibility for Attack on Macuto Stores

In August 2024, the Venezuelan department store chain Tiendas Macuto was the target of a ransomware attack by the Brain Cipher threat group. The incident, which was disclosed in mid-August and corroborated by multiple cybersecurity trackers, potentially exposed confidential business data as well as sensitive personal information, including first and last names, dates of birth, and ID numbers.

Overview

Missing evidence

Direct primary source from the threat actor’s leak site.Official statement or acknowledgment from Tiendas Macuto.Venezuelan national news coverage of the incident.

Impact details

Brain Cipher claimed to have stolen 300GB of corporate data from Tiendas Macuto and threatened to publish it. CCInfo and Hackmanac corroborate the existence of the claim/list, but no official confirmation from the victim, independent validation of the content, or public evidence of operational disruption has been found.

alleged corporate data

Classification & severity

Category
Malicious code
Subtype
Ransomware
Confidence
Medium

Brain Cipher listed Tiendas Macuto on its website dedicated to extortion, and several tracking services reported the ransomware demand, which included an alleged theft of 300 GB. No confirmation has been found from the victim.

Severity assessment

Medium
Information impact
Proprietary data
Affected scope
Organization-wide
Critical service
None
Public confidence
Moderate
Recoverability
Extended

Ransomware extortion and data theft are supported by trackers, but the actual scope and the publication of data have not been confirmed by the victim.

Data exfiltration· Claimed Confidentiality

Timeline

Claim

Brain Cipher listed Tiendas Macuto as an alleged victim.

Evidence & sources

3 sources