Ransomware victim disclosure
← All victimsEASY JOB S.A.S.
Claimed by Emperador · listed 3 days ago
Status timeline
- ListedSep 10, 2026
- Data leakeddate unknown
At a glance
- Group
- Emperador
- Status
- Data leaked
- Country
- Colombia
- Sector
- Professional Services
- Listed on leak site
- Sep 10, 2026
About the victim
AI dossier — public-source company profileEasy Job SAS is a Colombian professional services firm specializing in accounting, tax audit, and financial advisory. Based in Medellín, the company offers services including fiscal audit, tax compliance, payroll management, and IFRS consulting to business clients. They claim over 5 years of market experience.
- Industry
- Accounting, Tax & Financial Advisory Services
- Address
- Calle 17 sur 44 - 159 Oficina 1501 EDIFICIO CLAROSCURO, Medellín, Colombia
Attack summary
Severity: high — Confirmed exfiltration of 17,000 documents including employee and customer personal data, tax records, and financial databases. This represents regulated PII at scale in a financial services context, affecting both the firm's staff and its client base.The grupo emperador claims to have exfiltrated 17,000 documents (2.7 GB) containing personal data of employees and customers, tax documents, and databases from Easy Job SAS.
Data the group says was taken
AI dossier — extracted from the leak post- employee personal data
- customer personal data
- tax documents
- financial databases
- business records
What the group claims
Colombian Company. Audit and Tax Audit with more than 5 years of experience Calle 17 sur 44 - 159 Oficina 1501 EDIFICIO CLAROSCURO, Medellín Colombia. Llámanos o escríbenos: 310 447 2013 - 313 796 9917 The archives contain personal data of employees and customers of the company, tax documents, databases and other important documents 17000 documents [Size: 2.7 GB | Sector: Finance]
Sources
- Victim siteeasyjobsas.com
- Leak post/post/easy-job-sas/
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

