🚨 CYBERINTEL ALERT: PARTIAL DATA EXFILTRATION FROM AI AGENT (WATSON) – CEMIG (BRAZIL) 🇧🇷⚡📂🔓 "UNDER INVESTIGATION"
A critical data leak has been detected affecting CEMIG (Companhia Energética de Minas Gerais), the primary energy company in the state of Minas Gerais, Brazil. The threat actor, identified as "tarot," claims to have seized control of the IBM Watson Artificial Intelligence (AI) agent utilized by the company, exfiltrating the complete history of conversations and customer data spanning from September 2022 through April 2026.
🏢 Affected Entity: CEMIG (Energy Sector, Brazil).
🤖 Provider / Vector: IBM Watson (AI Agent / Virtual Assistant).
👤 Threat Actor: tarot
📊 Sample Volume (0.7%): 474,519 unique PII records.
📅 Compromise Period: September 2022 – April 2026.
📊 Scope of Shared Samples (PII and Infrastructure Data)
The actor has disclosed exact metrics regarding the partial data dump released, exposing:
243,328 Unique conversations.
158,388 Unique phone numbers.
42,750 Unique email addresses.
30,053 Unique CPFs (Cadastro de Pessoas Físicas – Brazilian tax identification numbers).
The technical sample (JSON) reveals a complete capture of the payload from the telecommunications infrastructure and the AI engine, including:
Full Identity: Account holder, CPF, email address, and phone number (Terminal: ).
Residential and Facility Data: Addresses.
Financial Data (Debts): Exact records of overdue balances and outstanding amounts (e.g., valorAberto: ) with corresponding due dates. SIP Infrastructure and Routing: Exposure of internal IPs (10.10.13.41), SIP URIs, and Voice Gateway parameters (vgwTenantID, SIP_HOST).
Literal Transcript: Log of the dialogue between the customer and the CEMIG bot (input.text, output.text).
🛡️ Immediate Response Recommendations
🔒 AI Vector Lockdown: CEMIG and IBM must immediately audit and isolate the data flow of the Watson agent (workspaceId: wa-cemig) to halt any ongoing exfiltration.
👁️ Customer Fraud Alert: Issue a mass alert (SMS/Email/Media) warning customers in Minas Gerais of the high risk of receiving fraudulent billing demands or WhatsApp messages containing their exact installation details.
Monitor:
analyzer.vecert.io
#CyberSecurity #Brazil #CEMIG #DataBreach #IBMWatson #AIHack #CPFLeak #InfoSec #CyberAlert #VECERT 🇧🇷🛡️⚠️🚨⚡