The ransomware claim targets Legis, a long-running Latin American legal and business information publisher, and alleges data access/exfiltration including SQL databases, legal documents, shareholder and ID copies, customer contract records, and detailed finance/ownership and litigation logs tied to business operations. The threat actor “rhysida” is named in connection with these alleged compromises, with impacts to Colombia, Venezuela, Argentina, Mexico, Peru, and Chile #Colombia#Venezuela#Argentina#Mexico#Peru#Chile
Incident Details
Information
- Well-known Latin American publisher specializing in legal and business information resources, serving professionals across Colombia, Venezuela, Argentina, Mexico, Peru, and Chile.
- Databases in SQL and PST/OST files were reportedly exposed.
- Legal documents reportedly included constitutional actions with claimants’ personal data, ID card copies of shareholders and third parties, environmental sanction proceedings, pension authority sanction disputes, signed cease-and-desist material related to a trademark dispute, personal data transfer agreements, litigation logs, and contract/payment/reorganization documents.
- Finance and ownership records reportedly included shareholder and ultimate beneficial owner registers with ID copies, ownership structure details, dividend payment records, debt write-off letters, and financial and tax reporting.
- Customer data reportedly included databases of law firms, universities, government contractors, and organizations such as Ecopetrol, Halliburton, and the AIM state agency, along with tax IDs, contacts, and contract history.

Disclaimer: This post is based on public claims made by the ransomware group "rhysida". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.