Ransomware linked to emperador reportedly compromised the MINISTÉRIO DA FAZENDA / SECRETARIA DA RECEITA FEDERAL DO BRASIL systems, exfiltrating thousands of documents containing personnel and customer data. The threat actor also accessed user data across gov.br, including passwords, impacting #Brazil.
Incident Details
- Victim: RECEITA FEDERAL DO BRASIL
- Sector: Government & Defense
- Country: BR
- Actor: emperador
- Source: http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/receita-federal-do-brasil/
- Discovered: 2026-09-23T09:20:59.298791+00:00
- Published: 2026-09-23T07:57:00+00:00
Information
- The archives contain several thousand documents with personnel and customer data, as well as all user data on gov.br with passwords.

Disclaimer: This post is based on public claims made by the ransomware group "emperador". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.