Ransomware victim disclosure
← All victimsJudicial Branch of the Province of Jujuy
Claimed by Emperador · listed 4 hours ago
Status timeline
- ListedSep 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Emperador
- Status
- Data leaked
- Country
- Argentina
- Sector
- Government & Defense
- Listed on leak site
- Sep 5, 2026
About the victim
AI dossier — public-source company profileThe Judicial Branch of the Province of Jujuy is the court system serving Jujuy Province, Argentina. It provides court information, digital case management, mediation services, and legal rulings for legal professionals and the public.
- Industry
- Government & Defense / Judiciary
Attack summary
Severity: critical — Confirmed exfiltration of government/judiciary infrastructure including administrative credentials and court databases affecting a provincial judicial system. Compromise of sensitive legal, case, and administrative data at the provincial court level constitutes critical infrastructure and regulated government data exposure.The emperador group claims to have compromised the organization's WordPress databases, internal system login credentials, and email credentials. A total of 4.2 GB of data has been exfiltrated. The group demands ransom and instructs the victim to check email and spam folders for contact details.
Data the group says was taken
AI dossier — extracted from the leak post- WordPress databases
- Internal system login credentials
- Email credentials
- Court information and case management systems
What the group claims
The official website of the Judicial Branch of Jujuy, Argentina. It provides court information, digital case management, mediation services, legal rulings, and judicial news for legal professionals and the public. Now i have your wordpress databases, login credentials to internal systems(thanks to marcos :)), as well as your email credentials Respond to us, pay the ransom.(Check your emails & check spam as well.) [Size: 4.2 GB | Sector: Government, Law]
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

