Emperador ransomware group claims breach of Uniguaçu (Brazilian education sector)
Emperador ransomware group claims breach of Uniguaçu (TL-2026-2207) is a medium-severity ransomware operation, first published 2026-08-29. It is attributed to Emperador with low confidence, affects Uniguaçu (Centro Universitário Vale do Iguaçu) Institutional IT, maps to 9 MITRE ATT&CK techniques (T1078, T1090.003, T1114), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-2207
- Threat ID
- TL-2026-2207
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-08-29
- Last reviewed
- 2026-08-29
- Attribution
- Emperador
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- education
- Target regions
- 005 - South America
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Emperador ransomware group claims breach of Uniguaçu
Malware and tooling: Emperador
The newly observed extortion group 'Emperador' posted a leak-site claim against Uniguaçu (Centro Universitário Vale do Iguaçu), a Brazilian higher-education institution, alleging full network access and theft of ~151.0 MB of confidential and financial data, including images the actor describes as compromising to the financial sector. The group set a 13-day negotiation deadline (through 2026-09-11). The claim is unverified and consistent with Emperador's established pattern of rapid, unverified leak-site postings against a broad cross-section of sectors since first appearing on 2026-08-10.
How Emperador ransomware group claims breach of Uniguaçu works
On 2026-08-29 at 15:21 UTC, the ransomware/data-extortion group self-identified as 'Emperador' listed Uniguaçu — the trading name of Centro Universitário Vale do Iguaçu, a private higher-education institution in União da Vitória, Paraná, Brazil, credentialed by Brazil's Ministry of Education in 2019 — on its Tor-hosted data-leak site. The posting claims 'full commitment of the network having full access to infrastructure' and theft of approximately 151.0 MB of confidential and financial data, including images the actor describes as compromising to the financial sector. One evidence screenshot is referenced on the tracker listing (filename 99f3df4207ac384a1a0e9f6496264b56.png). The group set a 13-day window from the claim date (deadline approximately 2026-09-11, shown as 2026-09-13 on RansomLook's own tracking table) and threatened unspecified 'severe measures' if payment is not made. As of this writing there is no independent corroboration of the intrusion, no confirmed exploited vulnerability, and no CVE associated with the claim — this is a leak-site extortion posting, not a confirmed technical compromise.
Emperador first appeared on ransomware-tracking platforms on 2026-08-10 with a claim against the City Government of Baguio (Philippines) and has posted at a rate of roughly one new victim every 1-3 days since (12 documented leak-site posts to date per RansomLook, with the group's Tor portal maintaining ~94% average uptime over the trailing 30 days), hitting government, education, energy/utilities, manufacturing, financial-services, technology, transportation, and food-production/consumer-staples targets across the Philippines, Albania, Brazil, Vietnam, Spain, South Korea and the United States. Mallory.ai ranks Emperador #36 of 8,601 tracked threat actors by current activity. RansomLook characterizes Emperador as operating a ransomware-as-a-service (RaaS)-style leak-site platform rather than a single fixed encryptor brand, describes its core TTPs as 'infrastructure compromise' via credential theft and administrative-access capture, database/financial-record exfiltration ahead of encryption, and a 'dual-encryption' double-extortion coercion model, and notes the group's selective targeting of critical-infrastructure and government entities assessed to have high financial capacity — consistent with a victim-reconnaissance step preceding each posting. For ransom negotiation, Emperador provides victims a Tox-protocol contact and a Session-messenger identifier (observed: Session ID 054e5b6edf03e8ba012626b5dcd83a7dd47a046760bcd9b9b32d02a039d24d9608) in addition to its .onion leak-site portal.
Independent trackers and blogs (RansomLook, Mallory.ai, GalaxyWarden, HookPhish, DeXpose) uniformly note that none of the public reporting to date includes forensic indicators (malware hashes, exploited CVEs, C2 IPs, or a confirmed initial-access vector) for any Emperador claim, including this one — every reviewed victim writeup explicitly flags itself as an unverified leak-site accusation rather than a confirmed technical breach report. Notably, for the Ipro.com/RevealData claim (2026-08-27), Emperador itself stated the data had 'previously appeared under a different alias on cracked.st' and that it was re-posting the material 'just for fun,' suggesting at least some Emperador postings may recycle previously circulated or unconfirmed data rather than reflect fresh intrusions — a caution that applies generally to interpreting the group's claims, including the Uniguaçu posting reviewed here. The Uniguaçu posting itself was made without an accompanying named CVE, malware sample, or infrastructure IOC beyond the group's own leak-site address and the referenced screenshot filename, consistent with Emperador's other postings reviewed for this report.
Mallory.ai's actor profile summarizes Emperador's claimed capability set as: the group is said to "exfiltrate databases, documents, financial records, personally identifiable information, and administrative credentials; encrypt victim systems; offer stolen data for sale; and threaten publication of stolen material when victims do not engage" — while cautioning that "the underlying compromise, exfiltration, and encryption claims have not been independently verified." Individual leak-site postings reviewed for other Emperador victims (e.g., the Prefeitura Municipal de Arcos entry on RansomLook) use standardized claim language of the form "We hold complete, unrestricted access to your internal infrastructure. All servers, databases, emails, and admin credentials have been exfiltrated," indicating email-store collection and administrative-credential harvesting are part of the group's consistent (self-reported) claim template rather than incident-specific detail.
MITRE ATT&CK techniques used in TL-2026-2207
Initial Access
Command and Control
Collection
T1114 Email Collection; T1213 Data from Information Repositories
Exfiltration
T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service
Credential Access
Reconnaissance
T1591 Gather Victim Org Information
Impact
Affected products and versions in Emperador ransomware group claims breach of Uniguaçu
- Uniguaçu (Centro Universitário Vale do Iguaçu) — Institutional IT infrastructure, student/financial databases
Vulnerable versions: N/A — no specific software, product, or version identified in the claim
Fixed in: N/A
Remediation for Emperador ransomware group claims breach of Uniguaçu
Patches
- No CVE or specific software vulnerability has been identified in this claim; patch guidance is not applicable pending forensic confirmation of an initial-access vector
Immediate actions
- Uniguaçu IT/security teams should independently verify the claim by reviewing authentication logs, EDR/AV alerts, and backup integrity before assuming compromise
- Rotate credentials for privileged, remote-access (VPN/RDP), and financial-system accounts as a precaution given the actor's 'full infrastructure access' and stated credential-theft/administrative-access-capture TTP
- Preserve forensic evidence (logs, disk images, network captures) and engage incident response before any contact with the extortion group
- Do not access or download the referenced leak-site screenshot or any linked data from the Emperador .onion site outside a controlled, isolated investigation environment
- Treat any ransom-negotiation contact (Tox ID, Session ID, or .onion portal) as hostile infrastructure — do not engage directly; route all contact through incident response/legal counsel
Workarounds
- None applicable — this is an unverified extortion/leak-site claim, not a disclosed technical vulnerability with a documented workaround
Longer-term hardening
- Enforce MFA on all remote-access and administrative accounts, and implement least-privilege review of admin/service accounts to blunt the 'Valid Accounts' abuse pattern reported for this group
- Deploy EDR with ransomware/exfiltration-behavior detection across endpoints, file servers, and database hosts, with emphasis on bulk database export and cloud-upload detection
- Run phishing-simulation and security-awareness training for staff — social engineering/credential theft is the suspected but unconfirmed initial-access vector reported for other Emperador victims
- Monitor Emperador's leak site and known ransomware trackers (ransomware.live, RansomLook, Mallory.ai) for updates or full-data publication tied to this claim
- Review and harden externally exposed services (VPN gateways, remote-access portals, financial/student-record applications) given the group's stated 'full infrastructure access'
- Given at least one Emperador claim (Ipro.com/RevealData) reused data previously circulated under a different alias on a criminal forum, cross-check any published Uniguaçu sample against known prior leaks before assuming a novel intrusion
Timeline of Emperador ransomware group claims breach of Uniguaçu
- Emperador group first observed on ransomware trackers, claiming City Government of Baguio (Philippines) as its first listed victim, alleging 2.9 GB of contracts, permits, and financial records
- Emperador claims Albania's national teacher training portal, alleging ~100k national ID records and teacher certificates (5.9 GB)
- Emperador claims Prefeitura Municipal de Arcos (Brazil), a government-sector victim, 462.3 MB claimed
- Emperador claims NetExam, an education/retail-sector victim, 18.1 MB claimed
- Emperador claims Vietnam Electricity (EVNHANOI), alleging over 300 GB including 13.36 million customer rows, 6.99 million subscriptions, and 2.26 million account records
- Emperador claims FRUCASTRO SL, a Spanish manufacturer, 540.1 MB claimed; full-publication deadline set for 2026-09-06
- Emperador claims both Capitol Mechanics (120.9 MB) and Ipro.com/RevealData (79.5 MB, a 2023 database backup the group says had previously circulated under a different alias on the cracked.st forum) on the same day
- Emperador claims Hanwha Renewables, an energy-sector victim, 12 GB claimed
- Emperador posts leak-site claim against Uniguaçu (15:21 UTC), alleging full infrastructure access and ~151.0 MB of confidential/financial data including compromising financial-sector images
- Emperador's stated full-publication deadline for the concurrent FRUCASTRO SL claim, illustrating the group's typical negotiation-window length
- Emperador's stated 13-day negotiation deadline for the Uniguaçu claim (RansomLook's own tracking table lists 2026-09-13); group has threatened unspecified further action if unmet
Sources cited for Emperador ransomware group claims breach of Uniguaçu
- Ransomware.live victim entry: Uniguaçu / Emperador
- Emperador — RansomLook group profile
- emperador — Mallory.ai threat actor profile
- Frucastro Sl Listed by Emperador Ransomware Group
- Ipro.com(revealdata.com) Listed by Emperador Ransomware Group
- Ransomware Group emperador Hits: Ipro.com(revealdata.com) customer DB + full database backup
- Ransomware Group emperador Hits: Albania's official national teacher training portal
- Emperador Ransomware Strikes Vietnam Electricity (EVNHANOI)
- Emperador Ransomware Attack Targets City Government of Baguio
- UNIGUAÇU — Centro Universitário Vale do Iguaçu institutional profile
More in ransomware
- Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas
- KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Software
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices
Detection coverage for TL-2026-2207
As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2207 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.