Arcos appears in Emperador leak
Brazil’s Arcos city hall appears on a leak site tied to Emperador, but the claim has not been independently verified.
Prefeitura Municipal de Arcos, in Brazil, appeared on a Ransomware.live listing attributed to Emperador and in threat intel alerts that describe a claimed intrusion and data theft. The information has not been independently verified by the municipality or by official agencies.
Prefeitura Municipal de Arcos, in Brazil, was listed by Ransomware.live as a victim of the Emperador group, with estimated discovery and attack dates of August 18, 2026. Several threat intelligence sources repeated the claim, but there is still no independent public confirmation from the municipality or from official agencies.
What was published about the case?
Hookphish published a dedicated note on the incident and reproduced the text of Emperador's alleged claim. According to that post, the group threatened to release the data if it did not receive a response within 14 days and classified the target under Government and Defense. Hookphish's technical sheet placed the breach at 07:24 UTC on August 18, 2026, the discovery at 07:51:43.694949 UTC the same day, the target domain as arcos.mg.gov.br, the region as BR, and the estimated data size at 462.3 MB, all presented as the group's claims.
GalaxyWarden, meanwhile, said the only verifiable fact was the existence of a public listing on Emperador's leak site with a 462.3 MB file sample attributed to Prefeitura Municipal de Arcos. Its entry stressed that neither the alleged breach, nor the exfiltration, nor any system encryption had been corroborated, and that the municipality had not confirmed any compromise.
What do the threat intel alerts say?
FalconFeeds.io reported that Prefeitura Municipal de Arcos had allegedly fallen victim to Emperador ransomware and pointed to 462.3 MB of compromised data, with publication expected in 13 to 14 days. Hackmanac issued a "Cyber Alert" on the same case, attributed to the group the claim that it had fully compromised internal infrastructure and listed exposed data of 0.46 GB, including databases and emails, while marking the status as "Pending verification."
Mallory.ai also included the case in Emperador's actor profile as ransomware and extortion activity against a Brazilian municipal agency. That profile repeats the claims about unauthorized access to internal infrastructure, theft of sensitive data, and encryption of critical systems, but presents them as information drawn from news and threat intel sources, not as a confirmed incident.
What is confirmed today?
What is confirmed so far is that there is a public post attributed to Emperador about Prefeitura Municipal de Arcos, and that several monitoring platforms picked it up. What has not been publicly corroborated is the alleged breach, the exfiltration of servers, databases, emails, and administrative credentials, or the encryption of critical systems. The actual scope of the material cited by the alerts also remains unconfirmed by official sources.
Sources
- Victim: Prefeitura Municipal de Arcos - Ransomware.liveransomware.live· Ransomware.live
- Ransomware Alert: Prefeitura Municipal de Arcos reportedly fallen victim to EMPERADOR ransomwarex.com· FalconFeeds.io
- Ransomware Group emperador Hits: Prefeitura Municipal de Arcoshookphish.com· Hookphish
- Prefeitura Municipal de Arcos Listed by Emperadorgalaxywarden.com· GalaxyWarden
- emperador - threat actor profile with Arcos listingmallory.ai· Mallory.ai
- Cyber Alert – Brazil - Prefeitura Municipal de Arcosx.com· Hackmanac / HackRisk



