Ncerio News blogCVE feed
What we measure across the estates we audit

icnavais.com — hit by lockbit5 ransomware

Brazilian defence firm ICN confirms LockBit 5 data extortion following site compromise.
22 August 2026

The domain icnavais.com has been identified as a victim of a ransomware incident involving the LockBit 5 group. This information was first reported via ransomlook.io, which maintains records of publicly disclosed data exfiltration events. The source directs readers to a specific entry detailing the breach at the provided URL.

The victim is identified as Itaguaí Construções Navais S.A., commonly referred to as ICN. This entity operates within the Brazilian defence sector and holds state-owned status. According to the summary provided by ransomlook.io, ICN is involved in naval construction activities, marking it as a significant player in Brazil's industrial defence landscape.

The attack methodology attributed to the perpetrators involves the use of LockBit 5, a known勒索 software family. The listing on ransomlook.io serves as the primary confirmation of this event. The platform aggregates data from various leak sites and announcements made by cybercrime groups when they claim responsibility for an intrusion.

Scope details regarding specific internal systems or exact volumes of data exfiltrated are not explicitly detailed in the brief summary available from the source. However, the classification under the ransomlook.io database indicates that sensitive information was likely extracted prior to encryption or disruption of services. The sector context places the incident squarely within state-backed defence infrastructure, highlighting the continued targeting of critical national assets.

The incident underscores the persistent threat landscape facing large-scale industrial and government-linked entities. As noted by the source, the involvement of state-owned defence companies continues to attract attention from sophisticated ransomware groups seeking high-value targets with substantial resources for negotiation. No further technical details on the initial access vector are currently available in this public report.

Source: icnavais.com — hit by lockbit5 ransomware — ransomlook.io
← all posts  ·  CVE feed