Ransomware victim disclosure
← All victimsIpro (Reveal)
listed as Ipro (revealdata.com) · Claimed by Emperador · listed 31 minutes ago
Status timeline
- ListedAug 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Emperador
- Status
- Data leaked
- Listed on leak site
- Aug 28, 2026
About the victim
AI dossier — public-source company profileIpro, operating under the Reveal brand, is a legal technology company founded in 2008 that provides AI-powered eDiscovery and data management solutions for law firms, corporations, government agencies, and legal service providers. The company offers a suite of products including Reveal (eDiscovery platform), Logikcull (discovery automation), Onna (data collection and management), and Reveal Hold (legal hold management).
- Industry
- Legal Technology / eDiscovery Software
- Founded
- 2008
Attack summary
Severity: critical — Confirmed exfiltration of customer database containing PII (contact/location), account data, and client relationships for a legal technology platform serving law firms and enterprises. Exposure of legal case transcripts and work product constitutes highly sensitive legal data at scale. The attacker claims to have posted this data before, suggesting actual publication occurred.The threat actor claims to have exfiltrated Ipro's customer database and a full database backup from 2023. The group states the data contains customer identifiers, contact and location information, account metadata, internal system IDs, and client relationships, as well as transcripts and cases from the backup.
Data the group says was taken
AI dossier — extracted from the leak post- Customer identifiers
- Contact and location information
- Account metadata
- Internal system IDs
- Client relationships
- Transcripts
- Cases
- Full database backup
What the group claims
Customer database and full database backup posted publicly. Data includes customer identifiers, contact and location information, account metadata, internal system IDs, client relationships, transcripts, and cases. Database backup is from 2023. Posted by current actor claiming prior posting under a different alias on cracked.st was fraudulent.
The leak post
captured from the group's siteIpro.com(revealdata.com) customer DB + full database backup Yes, this data has been posted before by ME under a different alias, yes the individual that posted the data on cracked.st is a fraud. I am posting this just for fun. Data contains:Customer identifiers, Contact & Location, Account metadata, Internal System IDS, Client relationships. The full database backup contains everything such as transcripts, cases, though it is from 2023.
Data the group says was taken
- customer identifiers
- contact information
- location data
- account metadata
- internal system IDs
- client relationships
- transcripts
- cases
- full database backup
Screenshot of the leak post

Sources
Source
Indexed 31 minutes agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

