Ransomware victim disclosure
← All victimsRECEITA FEDERAL DO BRASIL
Claimed by Emperador · listed 2 hours ago
Status timeline
- ListedSep 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Emperador
- Status
- Data leaked
- Country
- Brazil
- Sector
- Government & Defense
- Listed on leak site
- Sep 23, 2026
About the victim
AI dossier — public-source company profileReceita Federal do Brasil (Brazilian Federal Revenue Service) is the tax and revenue administration agency of Brazil's Ministry of Finance, responsible for federal tax collection, customs, and financial oversight.
- Industry
- Government & Defense
Attack summary
Severity: critical — Exfiltration of credentials and PII from a major Brazilian government tax agency represents a critical threat to national infrastructure, citizen privacy, and financial security. Compromise of gov.br authentication undermines trust in multiple government systems.The grupo Emperador claims to have exfiltrated several thousand documents containing personnel data, customer records, and user credentials (including passwords) from gov.br systems.
Data the group says was taken
AI dossier — extracted from the leak post- personnel records
- customer data
- gov.br user accounts with passwords
What the group claims
MINISTÉRIO DA FAZENDA SECRETARIA DA RECEITA FEDERAL DO BRASIL The archives contain several thousand documents with personnel and customer data, as well as all user date on gov.br with passwords. [Sector: Finance]
The leak post
captured from the group's siteMINISTÉRIO DA FAZENDASECRETARIA DA RECEITA FEDERAL DO BRASILThe archives contain several thousand documents with personnel and customer data,as well as all user date on gov.br with passwords.
Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

