SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
█ Ransomware TOTVS-DIREWOLF-RAN 2026-08-17

TOTVS: Direwolf Ransomware Leak Site Listing

"The Direwolf (also written Dire Wolf) ransomware group added Brazilian ERP and business-software vendor TOTVS to its Tor leak site on August 15, 2026, claiming stolen data touching client sectors from agriculture and…"

The Direwolf (also written Dire Wolf) ransomware group added Brazilian ERP and business-software vendor TOTVS to its Tor leak site on August 15, 2026, claiming stolen data touching client sectors from agriculture and education to energy, financial services and government. The listing was picked up the same day by Ransomware.live and by ThreatMon, whose feed timestamps the post at August 16, 2026 at 03:03 UTC+3 (August 15 in Brazilian local reporting). As of this writing there is no TOTVS statement, no regulator filing and no published record count from any source in this set. Every claim about scope originates with the extortion crew itself, and both outlets covering it flag the entry as an unverified claim rather than a confirmed breach.

What Happened

Direwolf's post names TOTVS as a victim with an attack date of August 15, 2026. TOTVS is one of Latin America's largest enterprise software firms, and a compromise there is a supply-chain event by definition: the sectors listed by the group are its customer verticals, not its own lines of business.

Accounts of the listing's breadth differ. The Ransomware.live-derived writeup (S1) enumerates twelve sectors: agriculture, education, energy, financial services, government, healthcare, hospitality, manufacturing, professional services, retail, technology and transportation. UndercodeNews (S4), working from ThreatMon's feed, describes the victim more narrowly as a "Brazilian technology company" and places it alongside a second listing, DXS International, posted in the same batch. Neither source shows leaked samples.

One detail deserves emphasis because it is easy to over-read. S1 notes the TOTVS victim entry is a duplicate, and speculates TOTVS "may have been targeted multiple times." Duplicate entries on leak-site aggregator feeds are frequently an artifact of the same post being scraped twice or re-published by the actor, not proof of a second intrusion. The pattern is visible elsewhere in the same feed, which carries two near-identical Emperador entries for Albania's national teacher training portal. Treat the duplicate as a data-quality flag, not as evidence of repeat compromise.

What Was Taken

No source in this set quantifies the theft. There is no file count, no data volume, no record total and no sample tree, from the group, from monitoring platforms or from TOTVS. Any figure circulating elsewhere is not supported here.

What the listing does advertise is a set of categories rather than a dataset: S1 reports the entry includes information on compromised employees, users, third-party credentials and external attack surface. That framing is characteristic of leak sites that bundle an intrusion claim with reconnaissance-style exposure data to increase negotiating pressure, and it is not the same thing as demonstrated exfiltration of customer ERP records.

Direwolf operates a double-extortion model, so the claim implies both encryption and data theft. Singapore's Cyber Security Agency has documented the group's use of file encryption paired with publication threats, per UndercodeNews. Whether either half occurred at TOTVS is unestablished. UndercodeNews states plainly that no publicly available evidence it reviewed shows what data, systems or services may have been affected.

Why It Matters

The exposure model here is downstream, not upstream. TOTVS Protheus and its adjacent modules sit inside payroll, financial close, inventory and public-sector procurement workflows across Brazil. If Direwolf holds genuine TOTVS-side data, the population at risk includes municipalities, agribusiness co-ops, hospitals and banks that never had a direct relationship with the attacker.

The listing also fits a visible run of Brazilian targeting by this crew. On August 10, 2026, Direwolf listed Chat Jurídico, a Brazilian legal-technology platform handling WhatsApp, CRM and AI-assisted case intake for law firms, per HookPhish and UndercodeNews, alongside a separate claim against US healthcare provider Leafwell. HookPhish records the Chat Jurídico breach date as 2026-08-10 21:39 UTC with discovery at 21:56 UTC. Three Brazilian or Brazil-adjacent software providers inside six days points at a deliberate regional software-vendor campaign rather than opportunistic spray.

Direwolf is not a legacy brand. ID Ransomware first identified the family on May 29, 2025, with activity observed from late May into June 2025. It is written in Go, encrypts with Curve25519 plus ChaCha20, appends .direwolf to encrypted files and drops a ransom note named HowToRecoveryFiles.txt. Victims have been recorded across the US, Thailand, Australia, Bahrain, India, Italy, Canada, Mexico, Singapore, Taiwan and France. Broadcom's research characterises the operation as human-operated with a focus on manufacturing and technology, which is consistent with an ERP vendor being chosen on purpose.

The Attack Technique

Initial access at TOTVS is unknown. No source identifies an entry vector, a vulnerability, a ransom demand or a negotiation status. What follows is exposure context, not attribution.

The leak-site metadata's emphasis on compromised employee and third-party credentials points toward credential abuse or phishing as the likely access path, which is the analyst read offered in S1 and matches Direwolf's human-operated profile. Third-party and contractor accounts are the weak seam in this model because they routinely carry production access without the monitoring applied to employee identities.

Two published TOTVS product flaws are worth pulling into the picture, with the caveat that neither has been linked to this incident:

Both are low-EPSS, low-probability items in isolation. Chained, an open redirect that lends credibility to a credential-harvesting page plus an MFA bypass on the core ERP framework describes a realistic path into a Protheus environment. Treat that as a hypothesis to hunt against, not a finding.

What Organizations Should Do

  1. Audit TOTVS deployment versions now. Confirm whether Protheus instances are on 12.1.2310 or older and whether Portal Meu RH is at or below 12.1.17. Patch to 12.1.2410.274, 12.1.2502.178 or 12.1.2506.121 as applicable, and prioritise the CVE-2024-55210 MFA bypass over the disputed open redirect.
  2. Hunt retroactively from August 10 to 15, 2026. Review TOTVS portal and Protheus authentication logs for anomalous websocket traffic, MFA-satisfied logins from unfamiliar ASNs or geographies, and password reset flows with unexpected redirect parameters. Direwolf's other Brazilian listings in that window make it a sensible lookback boundary.
  3. Rotate and re-scope third-party credentials. The listing highlights third-party employee credentials specifically. Inventory every integration, contractor and reseller account with access to ERP data, rotate secrets, enforce phishing-resistant MFA and remove standing access in favour of just-in-time grants.
  4. Segment ERP from everything else. Human-operated ransomware monetises lateral movement. Restrict east-west traffic to and from ERP application and database tiers, and alert on service accounts authenticating outside their normal path.
  5. Verify backup integrity offline. Direwolf uses Curve25519 and ChaCha20 with no known decryptor, and pairs encryption with publication threats, so backups address only half the problem. Test restores of ERP and financial data against immutable copies, and assume any stolen data stays stolen.
  6. Stage stakeholder communications before you need them. Incident communication guidance published in July 2026 notes that 38 percent of breach victims say company communication made things worse, and that poor communicators see roughly twice the customer churn of those who communicate proactively. Public companies face a four-business-day materiality disclosure clock under the SEC rules effective December 2023, and GDPR allows 72 hours for notifying supervisory authorities. Draft board, employee and customer templates in advance.

A closing note on posture: this brief documents a criminal claim on a leak site. Downstream TOTVS customers should act on the exposure hypothesis because the cost of patching and rotating credentials is low, but they should not treat the sector list as a confirmed inventory of stolen data until TOTVS or a regulator says otherwise.

Sources: 🏴‍☠️ Direwolf has just published a new victim : TOTVS Today In Cyber | CVE-2025-9193 Tenable® | CVE-2024-55210 Tenable® | Dire Wolf Ransomware Claims Two More Victims: DXS International and... | DireWolf Ransomware Claims Target Brazilian Legal Services Firm and... | Security Incident Communication Guide 2026: Board and Customer Temp... | Шифровальщики-вымогатели The Digest "Crypto-Ransomware": DireWolf | Ransomware Group direwolf Hits: Chat Jurídico