Ransomware victim disclosure
← All victimsAmazon Informática LTDA
listed as Amazon Informatica · Claimed by Emperador · listed 7 hours ago
Status timeline
- ListedSep 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Emperador
- Status
- Data leaked
- Country
- Brazil
- Sector
- Technology
- Listed on leak site
- Sep 28, 2026
About the victim
AI dossier — public-source company profileAmazon Informática LTDA is a Brazilian IT solutions integrator and managed services provider founded in 1995, primarily serving public sector and government agencies across Brazil. The company maintains offices in Brasília and Belém, with expanded operations in Latin America and Europe (Portugal), delivering government technology solutions and enterprise infrastructure support.
- Industry
- Information Technology Solutions & Managed Services
- Address
- Brasília/DF and Belém/PA, Brazil; international offices in Latin America and Europe (Portugal)
- Founded
- 1995
Attack summary
Severity: critical — Confirmed exfiltration claim of regulated sensitive data at scale including government-sector PII, financial credentials, and national identification records; full infrastructure compromise with exposed administrative access.The grupo emperador claims full network compromise with administrative access to production and integration database clusters. The attacker alleges exfiltration of sensitive personally identifiable information (PII), employee records, banking credentials, CPF (Brazilian tax ID), and RG (national ID) data, with database credentials exposed in plain text within compromised infrastructure files.
Data the group says was taken
AI dossier — extracted from the leak post- Production and integration databases
- Employee registries
- Banking credentials
- CPF data (Brazilian tax IDs)
- RG data (Brazilian national IDs)
- PII schemas
- Administrative credentials
What the group claims
Amazon Informática LTDA is a prominent Information Technology (IT) solutions integrator and managed services provider founded in Brazil in 1995. Amazon Informática's primary market focus is the public sector and government agencies, serving various state and federal entities in Brazil.To support these operations, they maintain strategic corporate offices in Brasília/DF (to service the federal government cluster) and Belém/PA. Furthermore, the company has expanded its footprint internationally with operational branches in Latin America and Europe (Portugal), where they deliver customized government tech solutions and enterprise infrastructure support to large private corporations in those regions. Full commitment of the network having full access to infrastructure, thus ensuring full access to the databases containing confidential and financial information! Virtual Infrastructure and Database Cluster with active administrative master credentials exposed in text clear inside get_bk.bat. Hosts compromised. The targets contain production and integration databases with sensitive PII schemas, employee registries, banking credentials, CPF, and RG data. TOX ID: 3D6EF83C3C4517FE42B212A934D4B08579A5F20522828C4E4818EA117F53063377C4D769640B SESSION: 052a5fe97f7b1822c2225ba884b5f719c07ec99da7d838421a20958938f54cb539 [Sector: Government, Technology]
The leak post
captured from the group's siteAmazon Informática LTDA is a prominent Information Technology (IT) solutions integrator and managed services provider founded in Brazil in 1995. Amazon Informática's primary market focus is the public sector and government agencies, serving various state and federal entities in Brazil.To support these operations, they maintain strategic corporate offices in Brasília/DF (to service the federal government cluster) and Belém/PA. Furthermore, the company has expanded its footprint internationally with operational branches in Latin America and Europe (Portugal), where they deliver customized government tech solutions and enterprise infrastructure support to large private corporations in those regions. Full commitment of the network having full access to infrastructure, thus ensuring full access to the databases containing confidential and financial information! Virtual Infrastructure and Database Cluster with active administrative master credentials exposed in text clear inside get_bk.bat. Hosts compromised. The targets contain production and integration databases with sensitive PII schemas, employee registries, banking credentials, CPF, and RG data.
Sources
Source
Indexed 7 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

