Ransomware victim disclosure
← All victimsElectrolux Group
Claimed by Emperador · listed 2 hours ago
Status timeline
- ListedSep 20, 2026
Current state: Listed for ransom
At a glance
- Group
- Emperador
- Status
- Listed for ransom
- Country
- Sweden
- Sector
- Manufacturing
- Listed on leak site
- Sep 20, 2026
- Data size
- 41GB
About the victim
AI dossier — public-source company profileElectrolux Group is a Swedish multinational manufacturer of home appliances, including refrigerators, washing machines, ovens, dishwashers, and vacuum cleaners, sold under multiple brands globally.
- Industry
- Home Appliances Manufacturing
Attack summary
Severity: high — Confirmed exfiltration of 41GB of data from a major multinational corporation's Azure database. Although the specific data types are not detailed, the scale and corporate scope indicate significant business data exposure. No proof files or screenshots are advertised in the post.The grupo claims to have accessed an Azure database and exfiltrated approximately 41GB of data. The attacker states the data is password-locked in an archive and threatens to release it and the password if a ransom is not paid.
Data the group says was taken
AI dossier — extracted from the leak post- Azure database contents
- Company data (unspecified types)
What the group claims
Swedish multinational home-appliance manufacturer, producing refrigerators, washing machines, ovens, dishwashers, vacuum cleaners, and other household appliances under several brands worldwide. Attackers claim to have accessed their Azure database and exported approximately 41GB of data.
The leak post
captured from the group's siteElectrolux Group is a Swedish multinational home-appliance manufacturer, producing refrigerators, washing machines, ovens, dishwashers, vacuum cleaners, and other household appliances under several brands worldwide. We were able to access your azure database, and export every piece of data which adds up to ~41GB. You will receive an email shortly containing the instructions you need to proceed. Electro_backup.7z(~41gb uncompressed) is currently password locked, but if they do not pay the ransom, the password and the data WILL be leaked Time is ticking, Pay the ransom. If you are having issues receiving instructions, contact me at: [email protected] And if youre still having an issue with that... contact my session: 05651c7323273b723588d47455471ee9e27feb5187a30f2933554a705aacb38358
Data the group says was taken
- database
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

