Ransomware victim disclosure
← All victimsAudit and Tax Audit Medellín
Claimed by Emperador · listed 24 hours ago
Status timeline
- ListedSep 15, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileAudit and Tax Audit Medellín is a Colombian accounting and auditing firm based in Medellín with more than 5 years of operating experience. The company provides audit and tax services to clients.
- Industry
- Professional Services / Accounting & Auditing
- Address
- Calle 17 sur 44 - 159 Oficina 1501 EDIFICIO CLAROSCURO, Medellín, Colombia
Attack summary
Severity: high — Confirmed exfiltration of personal data (employees and customers) at scale (17,000 documents) combined with sensitive tax and financial records typical of an audit firm. The data scope and regulatory sensitivity (PII + financial/tax documents) elevates this to high severity.The emperor group claims to have exfiltrated 17,000 documents from the company, including personal data of employees and customers, tax documents, and databases.
Data the group says was taken
AI dossier — extracted from the leak post- employee personal data
- customer personal data
- tax documents
- company databases
- business documents
What the group claims
Colombian company specializing in Audit and Tax Audit with more than 5 years of experience, located at Calle 17 sur 44 - 159 Oficina 1501 Edificio Claroscuro, Medellín, Colombia.
The leak post
captured from the group's siteColombian Company.Audit and Tax Audit with more than 5 years of experienceCalle 17 sur 44 - 159 Oficina 1501 EDIFICIO CLAROSCURO, Medellín Colombia.Llámanos o escríbenos: 310 447 2013 - 313 796 9917The archives contain personal data of employees and customers of the company, tax documents, databases and other important documents17000 documents
Data the group says was taken
- personal data of employees
- personal data of customers
- tax documents
- databases
- important documents
Screenshot of the leak post

Sources
Source
Indexed 24 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

