Ransomware victim disclosure
← All victimsPrefeitura Municipal de Cássia, Minas Gerais
listed as Cássia MG Government (CASSIAS.MG.GOV) · Claimed by Emperador · listed 3 hours ago
Status timeline
- ListedOct 8, 2026
Current state: Negotiating
At a glance
- Group
- Emperador
- Status
- Negotiating
- Country
- Brazil
- Sector
- Government
- Listed on leak site
- Oct 8, 2026
About the victim
AI dossier — public-source company profileCássia is a municipal government entity in Minas Gerais state, Brazil, responsible for local public administration, health services, and citizen records. The organization operates under the domain cassias.mg.gov.br.
- Industry
- Government & Public Administration
- Address
- Cássia, Minas Gerais, Brazil
Attack summary
Severity: critical — Confirmed exfiltration of regulated sensitive data at scale: personal identification documents (RG, CPF, birth certificates), medical records (SUS), financial access, police records, and government credentials affecting an entire municipal population. This constitutes exposure of PII at scale plus government operational data.The Emperor group claims to have exfiltrated sensitive government data including credentials, judicial system access, financial records, police data, and personally identifiable information (SUS medical records, RG identity documents, birth certificates, CPF numbers). The group has published sample proof files and issued a negotiation deadline.
Data the group says was taken
AI dossier — extracted from the leak post- Government credentials
- Justice system access panels
- Financial sector access
- Police records
- SUS medical records
- RG (national identity documents)
- Birth certificates
- CPF (tax ID/national identity numbers)
- Municipal department records
The group's post references roughly 2 proof files.
What the group claims
Ransomware attack on the municipal government of Cássia, Minas Gerais, Brazil. Claimed data includes government credentials, justice panel access, financial sector data, police records, personal data, medical records (SUS), RG (CIN), birth certificates, and CPF identity numbers from CASSIAS.MG.GOV departments.
The leak post
captured from the group's sitenetwork commitment, from government credentials to justice panels, such as access to the financial sector, police, personal data, medical (SUS), RG(CIN), BIRTH CERTIFICATE, CPF (identity number in Brazil) among other data from CASSIAS.MG.GOV departments, we will give you a deadline to negotiate with us! [UBS TIPO I CÁSSIA-UBS 1 CÁSSIA.pdf](http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/cassias-mg-government/sample/24/) [Débitos Agrupados por Origem de Lançamento_2026-09-04_17_02_47 (1).pdf](http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/cassias-mg-government/sample/25/)
Data the group says was taken
- government credentials
- financial records
- police records
- personal data
- medical records
- identity documents (RG/CIN)
- birth certificates
- CPF numbers
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

