Ransomware victim disclosure
← All victimsUniguacu
Claimed by Emperador · listed 2 days ago
Status timeline
- ListedAug 29, 2026
- Data leakeddate unknown
At a glance
- Group
- Emperador
- Status
- Data leaked
- Listed on leak site
- Aug 29, 2026
- Data size
- 12 GB
About the victim
AI dossier — public-source company profileUniguacu is an organization in the education sector. No further details are available from public sources.
- Industry
- Education
Attack summary
Severity: high — Confirmed exfiltration claim of confidential and financial information with stated proof files (images); full infrastructure/database access claimed; active extortion demand with deadline.The threat actor claims to have obtained full network and infrastructure access, including access to a database containing confidential and financial information. The group states they have exfiltrated images as proof and set a 13-day deadline before threatening 'severe measures'.
Data the group says was taken
AI dossier — extracted from the leak post- confidential information
- financial information
- database records
What the group claims
full commitment of the network having full access to infrastructure, thus ensuring access to the database containing confidential and financial information! I obtained some images that compromise the financial sector. You have 13 days to trade. If the trade doesn't occur as planned, we will have to take severe measures. I sent some images to show the veracity of the attack. The warning has been given! [Size: 151.0 MB | Sector: Education]
The leak post
captured from the group's site[ full commitment of the network having full access to infrastructure, thus ensuring access to the database containing confidential and financial information! I obtained some images that compromise the financial sector. You have 13 days to trade. If the trade doesn't occur as planned, we will have to take severe measures. I sent some images to show the veracity of the attack. The warning has been given! ](http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/uniguacu/) [ The data contains really sensitive information from 4 PV projects looking for investment/financing of Hanwha. We extracted around 12GB of highly sensitive information relating to the following projects: - Bonanza Peak (3GB) - Boulder Solar III (0.7GB) - Obreron Portfolio (4.8GB) - Project Sprout (3.7GB) In the data we found highly sensitive information including: - PPAs - Financial models - Interconnection agreements - Engineering designs of the assets - Personal identifiable information - Sensitive reports, budgets, financial information Reach out to prevent the leak. Cost of litigation from counterparties for breach of confidentiality is way higher. Commercially, good luck negotiating after y…
Screenshot of the leak post

Sources
- Leak post/post/uniguacu/
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

