Ransomware victim disclosure
← All victimsUnknown Peruvian Printing Company
Claimed by Emperador · listed 4 hours ago
Status timeline
- ListedOct 6, 2026
Current state: Listed for ransom
At a glance
- Group
- Emperador
- Status
- Listed for ransom
- Country
- Peru
- Sector
- Printing & Packaging
- Listed on leak site
- Oct 6, 2026
- Records
- several thousand documents
About the victim
AI dossier — public-source company profileA Peruvian printing company specializing in commercial printing, packaging, labels, boxes, books, magazines, booklets and promotional products. No public website or further details available.
- Industry
- Commercial Printing & Packaging
Attack summary
Severity: medium — Confirmed exfiltration of personnel and customer data at scale ('several thousand documents'), but no proof files or screenshots are advertised in the post, and no regulated data categories are explicitly mentioned.The grupo emperador claims to have exfiltrated several thousand documents containing personnel and customer data from the company.
Data the group says was taken
AI dossier — extracted from the leak post- personnel records
- customer data
- business documents
What the group claims
A Peruvian company from the printing industry specializing in commercial printing, packaging, labels, boxes, books, magazines, booklets and promotional products.
The leak post
captured from the group's siteA Peruvian company from the printing industry.Commercial printing, packaging, labels, boxes, books, magazines, booklets and promotional products.The archives contain several thousand documents with personnel and customer data.
Data the group says was taken
- personnel data
- customer data
- documents
Screenshot of the leak post

Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

