Ransomware victim disclosure
← All victimsIpro.com (Reveal Data)
Claimed by Emperador · listed 3 days ago
Status timeline
- ListedSep 2, 2026
- Data leakeddate unknown
At a glance
- Group
- Emperador
- Status
- Data leaked
- Sector
- Technology / Legal Tech
- Listed on leak site
- Sep 2, 2026
About the victim
AI dossier — public-source company profileIpro.com, operating under the brand Reveal Data, is a legal technology company providing software and services to law firms and legal departments. The company maintains customer databases and case management systems used by legal professionals.
- Industry
- Legal Tech / Legal Services Software
Attack summary
Severity: high — Confirmed exfiltration of customer databases and case files containing contact information, account metadata, and legal transcripts/cases from a legal services provider. Scale and sensitivity of legal data, combined with potential PII of end-clients, warrants high severity despite the attacker's claim this is a re-upload posted 'for fun' rather than an active extortion.The grupo emperador claims to have exfiltrated the full customer database and a complete 2023 database backup from Ipro.com/Reveal Data. The group states this is a re-upload of previously disclosed data and explicitly notes it is posted 'just for fun', suggesting no active ransom demand.
Data the group says was taken
AI dossier — extracted from the leak post- customer identifiers
- contact and location information
- account metadata
- internal system IDs
- client relationships
- transcripts
- cases
What the group claims
Customer DB and full database backup. Data contains customer identifiers, contact and location info, account metadata, internal system IDs, client relationships, transcripts, and cases from 2023.
The leak post
captured from the group's site[ full commitment of the network having full access to infrastructure, thus ensuring access to the database containing confidential and financial information! I obtained some images that compromise the financial sector. You have 13 days to trade. If the trade doesn't occur as planned, we will have to take severe measures. I sent some images to show the veracity of the attack. The warning has been given! ](http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/uniguacu/) [ The data contains really sensitive information from 4 PV projects looking for investment/financing of Hanwha. We extracted around 12GB of highly sensitive information relating to the following projects: - Bonanza Peak (3GB) - Boulder Solar III (0.7GB) - Obreron Portfolio (4.8GB) - Project Sprout (3.7GB) In the data we found highly sensitive information including: - PPAs - Financial models - Interconnection agreements - Engineering designs of the assets - Personal identifiable information - Sensitive reports, budgets, financial information Reach out to prevent the leak. Cost of litigation from counterparties for breach of confidentiality is way higher. Commercially, good luck negotiating after y…
Data the group says was taken
- customer database
- customer identifiers
- contact information
- location data
- account metadata
- internal system IDs
- client relationships
- transcripts
- cases
Screenshot of the leak post

Sources
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

