Ransom! Electrolux & Ontrac (SEP-2026)

Ransom! Electrolux & Ontrac (SEP-2026)
Threat actor emperador claims it compromised Electrolux and OnTrac, threatening to release stolen data about employees if the victims do not respond within one week, after both allegedly refused to discuss the breach. The claim includes references to salary information release for OnTrac and a listed email/session, but no impacted country is provided: #countryname

Incident Details

  • Victim: Electrolux & Ontrac
  • Sector: Manufacturing
  • Country:
  • Actor: emperador
  • Source: http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/electrolux-ontrac/
  • Discovered: 2026-09-25T17:51:02.090231+00:00
  • Published: 2026-09-25T16:24:00+00:00

Information

  • The attackers claim they contacted the IT helpdesk while posing as threat researchers and were told, “We cannot talk about it.”
  • They threaten to release more stolen data within one week, starting with employee information.
  • They say they prefer to settle the matter directly.
  • They specifically threaten OnTrac with releasing salary information for all employees, alleging pay as low as $14.50 an hour.
  • They claim to have spoken with a former OnTrac employee who described the experience there as horrible.
  • Contact details and a session identifier were included in the message.

Disclaimer: This post is based on public claims made by the ransomware group "emperador". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live