Ransomware victim disclosure
← All victimsTập đoàn Điện lực Việt Nam (Vietnam Electricity / EVN)
listed as Vietnam Electricity (EVN / EVNHANOI) · Claimed by Emperador · listed 4 hours ago
Status timeline
- ListedAug 31, 2026
Current state: Listed for ransom
At a glance
- Group
- Emperador
- Status
- Listed for ransom
- Country
- Vietnam
- Sector
- Energy / Utilities
- Listed on leak site
- Aug 31, 2026
- Data size
- 300GB+
- Records
- 22,610,000+
About the victim
AI dossier — public-source company profileEVN is Vietnam's largest and sole national electric utility, fully government-owned since 1994. It operates as a vertically integrated monopoly responsible for nationwide generation, transmission, and distribution of electricity, as well as international power exchanges. The group oversees all major power plants and regional distribution subsidiaries including EVNHANOI.
- Industry
- Electric Utilities & Power Generation
- Founded
- 1994
Attack summary
Severity: critical — Confirmed exfiltration of massive-scale personally identifiable information (13.36M+ customer records) from critical national infrastructure; operational disruption via encryption of critical systems; government-owned strategic asset.The grupo claiming full access to EVN's infrastructure states they have exfiltrated 300GB+ of data including customer records, subscriptions, and account information. The group encrypted critical systems and is demanding negotiation within 14 days, threatening public data release.
Data the group says was taken
AI dossier — extracted from the leak post- Customer details (13.36 million records)
- Subscription records (6.99 million)
- Account records (2.26 million)
- Internal infrastructure data
- Databases and admin credentials
- Email systems
The group's post references roughly 3 proof files.
What the group claims
Vietnam Electricity (EVN), the largest power company and sole national electric utility in Vietnam, fully owned by the Vietnamese government. Data exceeds 300GB comprising customer details, subscriptions, and account records.
The leak post
captured from the group's site[ full commitment of the network having full access to infrastructure, thus ensuring access to the database containing confidential and financial information! I obtained some images that compromise the financial sector. You have 13 days to trade. If the trade doesn't occur as planned, we will have to take severe measures. I sent some images to show the veracity of the attack. The warning has been given! ](http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/uniguacu/) [ The data contains really sensitive information from 4 PV projects looking for investment/financing of Hanwha. We extracted around 12GB of highly sensitive information relating to the following projects: - Bonanza Peak (3GB) - Boulder Solar III (0.7GB) - Obreron Portfolio (4.8GB) - Project Sprout (3.7GB) In the data we found highly sensitive information including: - PPAs - Financial models - Interconnection agreements - Engineering designs of the assets - Personal identifiable information - Sensitive reports, budgets, financial information Reach out to prevent the leak. Cost of litigation from counterparties for breach of confidentiality is way higher. Commercially, good luck negotiating after y…
Data the group says was taken
- customer details
- subscription records
- account records
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

