Ransomware victim disclosure
← All victimsIpro.com (RevealData)
Claimed by Emperador · listed 4 hours ago
Status timeline
- ListedAug 31, 2026
- Data leakeddate unknown
At a glance
- Group
- Emperador
- Status
- Data leaked
- Sector
- Technology / Legal Tech
- Listed on leak site
- Aug 31, 2026
About the victim
AI dossier — public-source company profileIpro.com, operating under the brand RevealData, is a legal technology company providing database and case management solutions to legal professionals. The company maintains customer databases and archives including case transcripts and client relationship data.
- Industry
- Legal Tech / Legal Services Software
Attack summary
Severity: high — Confirmed exfiltration of sensitive business and customer data including PII (contact/location), client relationships, case information, and internal infrastructure details. Legal industry data is commercially sensitive and affects attorney-client confidentiality. Scale and nature of data (full database backup) indicates significant exposure.Emperador claims to have exfiltrated Ipro.com's complete customer database and full 2023 database backup containing customer identifiers, contact information, location data, account metadata, internal system IDs, and client relationships. The attacker notes the data was previously posted under a different alias and states this is a re-upload.
Data the group says was taken
AI dossier — extracted from the leak post- Customer identifiers
- Contact information
- Location data
- Account metadata
- Internal system IDs
- Client relationships
- Case transcripts
- Full database backup (2023)
What the group claims
Customer DB and full database backup from Ipro.com (revealdata.com). Data contains customer identifiers, contact and location info, account metadata, internal system IDs, client relationships, transcripts, and cases (from 2023).
The leak post
captured from the group's site[ full commitment of the network having full access to infrastructure, thus ensuring access to the database containing confidential and financial information! I obtained some images that compromise the financial sector. You have 13 days to trade. If the trade doesn't occur as planned, we will have to take severe measures. I sent some images to show the veracity of the attack. The warning has been given! ](http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/uniguacu/) [ The data contains really sensitive information from 4 PV projects looking for investment/financing of Hanwha. We extracted around 12GB of highly sensitive information relating to the following projects: - Bonanza Peak (3GB) - Boulder Solar III (0.7GB) - Obreron Portfolio (4.8GB) - Project Sprout (3.7GB) In the data we found highly sensitive information including: - PPAs - Financial models - Interconnection agreements - Engineering designs of the assets - Personal identifiable information - Sensitive reports, budgets, financial information Reach out to prevent the leak. Cost of litigation from counterparties for breach of confidentiality is way higher. Commercially, good luck negotiating after y…
Data the group says was taken
- customer identifiers
- contact information
- location data
- account metadata
- internal system IDs
- client relationships
- transcripts
- cases
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

