The ransomware threat claim involves emperador targeting Nexbex Solutions Private Limited, a technology consulting and software engineering firm based in Malappuram, Kerala (India), alleging access to 600 MB of client-sensitive databases containing names, emails, phone numbers, and addresses. The claimant also alleges compromise and theft of domains/subdomains and 10+ GB of source code across 200+ projects, impacting #India.
Incident Details
- Victim: Nexbex Solutions Private Limited
- Sector: Not Found
- Country:
- Actor: emperador
- Source: /post/nexbex-solutions-private-limited/
- Discovered: 2026-09-12T13:51:54.425309+00:00
- Published: 2026-09-11T22:46:00+00:00
Information
- Access to all databases containing clientsβ sensitive data, including names, emails, phone numbers, and addresses.
- Approximately 600 MB of data exfiltrated.
- Domains include club7ms.com, rayssportsnetwork.com, and hwzthat.com.
- Multiple subdomains were exposed, including staging, edmontoneagles, masc, psca, live, kkr, victoriapark, spartans, blaze, ramblers, and eagle.
- Additional administrative and backend-related subdomains were also identified, such as admin.bookings-staging, backend.academy, and admin.spike.booking.
- Source code for more than 200 projects was obtained, totaling over 10 GB and still growing.
Disclaimer: This post is based on public claims made by the ransomware group "emperador". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.