Cassias MG Government in Brazil was targeted by threat actor emperador using ransomware against government credentials and network access, later involving justice panels and sectors such as finance, police, and sensitive records. The data exposure included personal identity and civil documents (e.g., RG/CIN, birth certificates, CPF), along with medical information from Brazil’s SUS, threatening operational continuity under a negotiation deadline! #Brazil
Incident Details
- Victim: Cassias MG Government
- Sector: Government & Defense
- Country: BR
- Actor: emperador
- Source: http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/cassias-mg-government/
- Discovered: 2026-09-19T07:50:51.612488+00:00
- Published: 2026-09-19T07:14:00+00:00
Information
- Government credentials and access to justice panels
- Access to the financial sector
- Police-related information
- Personal data
- Medical data from the public health system (SUS)
- RG/CIN records
- Birth certificates
- CPF identity numbers
- Data from multiple departments of the CASSIAS.MG.GOV domain
- Demand for negotiation within a set deadline

Disclaimer: This post is based on public claims made by the ransomware group "emperador". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.