Ransomware victim disclosure
← All victimsNetExam (netexam.com)
Claimed by Emperador · listed 3 days ago
Status timeline
- ListedSep 10, 2026
Current state: Listed for ransom
At a glance
- Group
- Emperador
- Status
- Listed for ransom
- Country
- United States
- Listed on leak site
- Sep 10, 2026
- Data size
- 18.1 MB
- Records
- 17000 files
About the victim
AI dossier — public-source company profileNetExam LMS+ is a US-based SaaS learning management system headquartered in Dallas that enables companies to train, certify, and support their channel partners, customers, and association members. The platform offers certification tracking, self-paced and instructor-led courses, e-commerce, white-labeling, Salesforce integration, and AI-powered course authoring. Notable clients include AMD, AT&T, Oracle, Trellix, and Sabre.
- Industry
- Education Technology / Learning Management Systems (SaaS)
- Address
- Dallas, United States
Attack summary
Severity: high — Claimed exfiltration of complete infrastructure access including databases and credentials affecting a SaaS platform serving major enterprise clients (AMD, AT&T, Oracle). The threat to customer data and operational disruption of a learning platform used by significant organizations elevates this to high severity, though no specific regulated data categories (PII at massive scale, financial records, etc.) are explicitly detailed in the leak post.The Emperador group claims to have achieved complete access to NetExam's internal infrastructure, including all servers, databases, emails, and admin credentials. They claim to have exfiltrated data and encrypted critical systems, with a 14-day deadline for ransom response before data publication and permanent loss.
Data the group says was taken
AI dossier — extracted from the leak post- internal infrastructure access (servers, databases, emails, admin credentials)
- customer/client data
- configuration and system files
What the group claims
NetExam LMS+, a US-based SaaS learning management system built for external audiences. Helps companies train, certify, and enable channel partners, customers, and association members. Headquartered in Dallas, with clients including AMD, AT&T, Oracle, Trellix, and Sabre.
The leak post
captured from the group's site[ Bosnia and Herzegovina Mine Action Center ](http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/bosnia-and-herzegovina-mine-action-center/) [ ](http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/baymer/) [ ](http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/universal-starch-chem-allied-ltd/) [ Judicial Branch of the Province of Jujuy The official website of the Judicial Branch of Jujuy, Argentina. It provides court information, digital case management, mediation services, legal rulings, and judicial news for legal professionals and the public. Now i have your wordpress databases, login credentials to internal systems(thanks to marcos :)), as well as your email credentials Respond to us, pay the ransom.(Check your emails & check spam as well.) OR email me at : [email protected] for instructions ](http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/judicial-branch-of-the-province-of-jujuy/) [ full commitment of the network having full access to infrastructure, thus ensuring access to the database containing confidential and financial information! I obtained some images th…
Data the group says was taken
- customer data
Screenshot of the leak post

Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

