The ransomware claim targets the Prefeitura Municipal de Arcos in Brazil (BR) by the threat actor emperador, alleging full access and exfiltration of internal servers, databases, emails, and admin credentials. It further claims critical systems were encrypted and threatens publication and permanent data loss if no response is made within 14 days, contacting the attackers directly with no recovery attempts. #Brazil
Incident Details
- Victim: Prefeitura Municipal de Arcos
- Sector: Government & Defense
- Country: BR
- Actor: emperador
- Source: /post/prefeitura-municipal-de-arcos/
- Discovered: 2026-08-18T07:51:43.694949+00:00
- Published: 2026-08-18T07:24:00+00:00
Information
- Complete, unrestricted access to the internal infrastructure was obtained.
- Servers, databases, emails, and admin credentials were exfiltrated.
- Critical systems were encrypted.
- Data was taken and is being held.
- A 14-day deadline was issued for a response.
- Failure to respond was threatened with data publication and permanent loss.
- Contact was instructed only through the provided channel, with no third parties or recovery attempts.
- The affected data size was 462.3 MB.
- The sector involved was Government.
Disclaimer: This post is based on public claims made by the ransomware group "emperador". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.