Emperador ransomware group claims breach of Uniguaçu (Brazilian education sector) — Threadlinqs Intelligence
As of 2026-08-29, Emperador ransomware group claims breach of Uniguaçu (Brazilian education sector) is a medium-severity ransomware threat attributed to Emperador, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-2207 · Severity: MEDIUM · Status: ACTIVE · Category: RANSOMWARE
Attribution: Emperador · FINANCIAL
The newly observed extortion group 'Emperador' posted a leak-site claim against Uniguaçu (Centro Universitário Vale do Iguaçu), a Brazilian higher-education institution, alleging full network access
On 2026-08-29 at 15:21 UTC, the ransomware/data-extortion group self-identified as 'Emperador' listed Uniguaçu — the trading name of Centro Universitário Vale do Iguaçu, a private higher-education institution in União da Vitória, Paraná, Brazil, credentialed by Brazil's Ministry of Education in 2019 — on its Tor-hosted data-leak site. The posting claims 'full commitment of the network having full access to infrastructure' and theft of approximately 151.0 MB of confidential and financial data, including images the actor describes as compromising to the financial sector. One evidence screenshot is referenced on the tracker listing (filename 99f3df4207ac384a1a0e9f6496264b56.png). The group set a 13-day window from the claim date (deadline approximately 2026-09-11, shown as 2026-09-13 on RansomLook's own tracking table) and threatened unspecified 'severe measures' if payment is not made. As of this writing there is no independent corroboration of the intrusion, no confirmed exploited vulnerability, and no CVE associated with the claim — this is a leak-site extortion posting, not a confirmed technical compromise.
Emperador first appeared on ransomware-tracking platforms on 2026-08-10 with a claim against the City Government of Baguio (Philippines) and has posted at a rate of roughly one new victim every 1-3 days since (12 documented leak-site posts to date per RansomLook, with the group's Tor portal maintaining ~94% average uptime over the trailing 30 days), hitting government, education, energy/utilities, manufacturing, financial-services, technology, transportation, and food-production/consumer-staples targets across the Philippines, Albania, Brazil, Vietnam, Spain, South Korea and the United States. Mallory.ai ranks Emperador #36 of 8,601 tracked threat actors by current activity. RansomLook characterizes Emperador as operating a ransomware-as-a-service (RaaS)-style leak-site platform rather than a single fixed encryptor brand, describes its core TTPs as 'infrastructure compromise' via credential theft and administrative-access capture, database/financial-record exfiltration ahead of encryption, and a 'dual-encryption' double-extortion coercion model, and notes the group's selective targeting of critical-infrastructure and government entities assessed to have high financial capacity — consistent with a victim-reconnaissance step preceding each posting. For ransom negotiation, Emperador provides victims a Tox-protocol contact and a Session-messenger identifier (observed: Session ID 054e5b6edf03e8ba012626b5dcd83a7dd47a046760bcd9b9b32d02a039d24d9608) in addition to its .onion leak-site portal.
Independent trackers and blogs (RansomLook, Mallory.ai, GalaxyWarden, HookPhish, DeXpose) uniformly note that none of the public reporting to date includes forensic indicators (malware hashes, exploited CVEs, C2 IPs, or a confirmed initial-access vector) for any Emperador claim, including this one — every reviewed victim writeup explicitly flags itself as an unverified leak-site accusation rather than a confirmed technical breach report. Notably, for the Ipro.com/RevealData claim (2026-08-27), Emperador itself stated the data had 'previously appeared under a different alias on cracked.st' and that it was re-posting the material 'just for fun,' suggesting at least some Emperador postings may recycle previously circulated or unconfirmed data rather than reflect fresh intrusions — a caution that applies generally to interpreting the group's claims, including the Uniguaçu posting reviewed here. The Uniguaçu posting itself was made without an accompanying named CVE, malware sample, or infrastructure IOC beyond the group's own leak-site address and the referenced screenshot filename, consistent with Emperador's other postings reviewed for this report.
Mallory.ai's actor profile summarizes Emperador's claimed capability set as: the group is said to "exfiltrate databases, documents, financial records, personally identifiable information, and admin
Target sectors: education
Target regions: 005 - South America
Timeline
- Emperador group first observed on ransomware trackers, claiming City Government of Baguio (Philippines) as its first listed victim, alleging 2.9 GB of contracts, permits, and financial records
- Emperador claims Albania's national teacher training portal, alleging ~100k national ID records and teacher certificates (5.9 GB)
- Emperador claims Prefeitura Municipal de Arcos (Brazil), a government-sector victim, 462.3 MB claimed
- Emperador claims NetExam, an education/retail-sector victim, 18.1 MB claimed
- Emperador claims Vietnam Electricity (EVNHANOI), alleging over 300 GB including 13.36 million customer rows, 6.99 million subscriptions, and 2.26 million account records
- Emperador claims FRUCASTRO SL, a Spanish manufacturer, 540.1 MB claimed; full-publication deadline set for 2026-09-06
- Emperador claims both Capitol Mechanics (120.9 MB) and Ipro.com/RevealData (79.5 MB, a 2023 database backup the group says had previously circulated under a different alias on the cracked.st forum) on the same day
- Emperador claims Hanwha Renewables, an energy-sector victim, 12 GB claimed
- Emperador posts leak-site claim against Uniguaçu (15:21 UTC), alleging full infrastructure access and ~151.0 MB of confidential/financial data including compromising financial-sector images
- Emperador's stated full-publication deadline for the concurrent FRUCASTRO SL claim, illustrating the group's typical negotiation-window length
- Emperador's stated 13-day negotiation deadline for the Uniguaçu claim (RansomLook's own tracking table lists 2026-09-13); group has threatened unspecified further action if unmet
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, MEDIUM, threat intelligence, cybersecurity, T1591, T1078, T1552, T1213, T1114, T1537, T1567, T1090.003, T1657