Threat actor emperador claimed to have accessed Electrolux’s Azure database in Sweden (SE) and exfiltrated approximately 41GB of data, threatening to leak the password-locked archive Electro_backup.7z unless the ransom is paid. The actor said the victim would receive ransom instructions by email and warned that the password and data would be released if they did not comply. #Sweden
Incident Details
- Victim: Electrolux
- Sector: Manufacturing
- Country: SE
- Actor: emperador
- Source: http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/electrolux/
- Discovered: 2026-09-19T15:50:53.665077+00:00
- Published: 2026-09-19T00:00:00+00:00
Information
- Electrolux Group is a Swedish multinational home-appliance manufacturer producing refrigerators, washing machines, ovens, dishwashers, vacuum cleaners, and other household appliances under several brands worldwide.
- The attackers claim they accessed the Azure database and exported all data, totaling approximately 41 GB.
- Instructions for proceeding were said to be sent by email.
- They stated that the file Electro_backup.7z is password-protected and warned that if the ransom is not paid, the password and data will be leaked.
- They demanded payment and included a contact email for issues receiving instructions.

Disclaimer: This post is based on public claims made by the ransomware group "emperador". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.