CiberLATAMbywhalemate

Emperador posts OnTrac, Electrolux victims

Emperador added OnTrac and Electrolux to its leak site, claiming $1 million and up to 75.1 MB of exfiltrated data.

Whalemate Labs · AI-assisted researchPublished:2 min read

The ransomware group Emperador posted OnTrac and Electrolux on its leak site, with claims of $1 million in the OnTrac case and metadata showing 44.4 MB, then 75.1 MB, of exfiltrated data. Threat intelligence reports also link the group to other victims in the United States and to targets in Brazil, Spain, France, the United States, and Canada.

The ransomware group Emperador posted OnTrac and Electrolux on its leak site, with a $1 million demand in the OnTrac case and metadata showing 44.4 MB, then 75.1 MB, of exfiltrated data. The same set of reports also places it behind attacks on Alabama Woman's Health Care, while CYFIRMA links the group to targets in Brazil, Spain, France, the United States, and Canada.

What is known about the OnTrac case?

Emperador listed OnTrac as a victim and, according to Ransomware.live, the entry included a $1 million demand and 44.4 MB of exfiltrated data. Galaxy Warden also said the group claimed to have personal information from employees, although OnTrac had not publicly confirmed the claim at the time of reporting.

Daily Dark Web added that Emperador allegedly obtained about 197,000 OnTrac employee records and repeated the $1 million demand. That coverage also stressed there is no independent evidence establishing what data was taken or linking the case to a prior corporate breach at the company.

How does Electrolux appear in the same campaign?

Ransomware.live later recorded a separate Emperador post that included Electrolux and OnTrac, with 75.1 MB of exfiltrated data according to the metadata attached to that post. Galaxy Warden said the group claimed it had contacted both companies while posing as threat researchers, and threatened to publish more information, including OnTrac employee and salary data.

In that same report, Galaxy Warden said neither company had publicly confirmed the incident at the time of publication. The available material does not provide more detail on the contents of the files or the scope of the intrusion at Electrolux.

What other targets and sectors appear in the reports?

The Hacker Wire identifies Emperador as responsible for another U.S. victim, Alabama Woman's Health Care, a health organization. Class Action U said the group claimed to have obtained thousands of patient and employee documents, plus a photo file, but noted the organization had not publicly confirmed the incident or the extent of the data.

Separately, CYFIRMA's weekly report places ArcusMedia in focus across Brazil, Spain, France, the United States, and Canada. In that report, exposure in Latin American countries appears alongside North American and European markets, while Emperador's victim list remains concentrated so far in the United States and in recent posts on its leak site.

Sources

View all