> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Brazilian Construction Information Company PiniWeb Allegedly Breached, 13.9 GB Listed For Sale
- URL: https://darkwebinformer.com/brazilian-construction-information-company-piniweb-allegedly-breached-13-9-gb-listed-for-sale/
- Published: 2026-06-18T16:35:47.000Z
- Updated: 2026-06-18T16:35:47.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report ![Brazil flag](https://flagcdn.com/w40/br.png)Brazil Information Services 

## Brazilian Construction Information Company PiniWeb Allegedly Breached, 13.9 GB Listed For Sale

A threat actor using the alias **S0BER** is advertising the sale of a claimed **\~13.9 GB dataset of around 10,290 files** across three RAR archives, spanning **2003 to 2026**, said to be stolen from **PiniWeb / Editora Pini** (piniweb.com.br), a Brazilian information company that has served the construction industry since 1948\. According to the listing, the data allegedly includes subscriber and customer databases (LGPD-relevant personal data), government procurement records and tax invoices tied to public-sector and corporate clients, proprietary construction price-table data (SINAPI/TCPO), SQL scripts and database schemas, Outlook PST email archives, internal infrastructure and remote-access configurations, and a code-signing certificate. The seller themselves rates several categories as high or critical risk. The dataset's authenticity and scope are **unverified**.

Severity CRITICAL 

Data\~13.9 GB

PriceFor sale

Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil

ActorS0BER

### ▣Post details

TargetPiniWeb / Editora Pini (piniweb.com.br)

Country![Brazil flag](https://flagcdn.com/w40/br.png)Brazil

SectorInformation Services / Construction

Claim\~13.9GB / 10,290 files for sale

DataCustomer DBs, gov records, DB assets

Archives3 RAR files (2003-2026)

ObservedJun 18, 2026

ActorS0BER

### !Allegedly included

- \~10,290 files (\~13.9 GB)
- 3 RAR archives (2003-2026)
- Subscriber & customer databases
- Government procurement & NF-e records
- Proprietary SINAPI/TCPO price data
- SQL scripts & database schemas
- Outlook PST email archives
- Code-signing cert & infra configs

### ◱Screenshots

[ ![PiniWeb Brazil alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/823547823478652187654876215348761.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/823547823478652187654876215348761.png) [ ![PiniWeb Brazil alleged leak Screenshot 2](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/823547823478652187654876215348762.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/823547823478652187654876215348762.png) [ ![PiniWeb Brazil alleged leak Screenshot 3](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/823547823478652187654876215348763.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/823547823478652187654876215348763.png) 

### ⚠Potential impact

This sits in the critical tier because the listing allegedly combines several high-impact data types. On the personal-data side, subscriber, customer, and prospect databases plus PST email archives would expose LGPD-relevant personal information of individuals, along with references to several named employees. On the business side, government procurement records, tax invoices, and named public-sector bodies and corporate clients could expose sensitive commercial relationships. Most seriously from a security standpoint, the listing claims to include database schemas and SQL logic, internal infrastructure and remote-access (RDP) configurations, and a **code-signing certificate**. If a usable code-signing certificate is exposed it could let attackers sign malicious software as if it came from the company, which is why such a certificate would warrant immediate revocation; exposed infrastructure and database logic similarly raise the risk of follow-on intrusion. No purchase details, seller contacts, certificate contents, or technical specifics are reproduced here. Authenticity and scope are unverified.

### iStatus

Unverified 

A detailed file manifest and statistics were posted to an underground forum offering the data for sale; the sample data, certificate, specific infrastructure details, and seller contact information are **not** reproduced here. The claim has **not been independently confirmed** and PiniWeb / Editora Pini has not publicly addressed it.

Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE