Ransomware victim disclosure
← All victimsMINISTÉRIO DA FAZENDA - SECRETARIA DA RECEITA FEDERAL DO BRASIL
Claimed by Emperador · listed 2 hours ago
Status timeline
- ListedSep 24, 2026
Current state: Listed for ransom
At a glance
- Group
- Emperador
- Status
- Listed for ransom
- Country
- Brazil
- Sector
- Government
- Listed on leak site
- Sep 24, 2026
About the victim
AI dossier — public-source company profileThe Brazilian Federal Revenue Service (Secretaria da Receita Federal do Brasil), a department of the Ministry of Finance (Ministério da Fazenda), is responsible for federal tax collection, customs administration, and revenue enforcement across Brazil.
- Industry
- Government - Tax & Revenue Administration
- Address
- Brasília, Brazil
Attack summary
Severity: critical — Alleged exfiltration of PII at scale (personnel and customer data), government employee credentials, and passwords from a core Brazilian federal tax/revenue authority. This represents compromise of a critical government infrastructure entity with access to sensitive taxpayer and administrative information.The group claims to have exfiltrated several thousand documents containing personnel and customer data, as well as user accounts and passwords from gov.br government systems.
Data the group says was taken
AI dossier — extracted from the leak post- Personnel records
- Customer data
- Government employee accounts
- Login credentials (passwords)
- Gov.br system data
What the group claims
Archives contain several thousand documents with personnel and customer data, as well as all user data on gov.br with passwords.
The leak post
captured from the group's siteMINISTÉRIO DA FAZENDASECRETARIA DA RECEITA FEDERAL DO BRASILThe archives contain several thousand documents with personnel and customer data,as well as all user date on gov.br with passwords.
Data the group says was taken
- personnel data
- customer data
- user credentials
- passwords
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

