CiberLATAMbywhalemate

Jujuy Judiciary exposed by Emperador ransomware

Emperador leaked WordPress databases and credentials from Jujuy’s judiciary. The operation is still active and has another confirmed victim.

Whalemate Labs · AI-assisted researchPublished:3 min read

The Judiciary of Jujuy Province is listed as a confirmed victim of the Emperador ransomware group, with exposed WordPress databases, internal system access credentials, and email credentials. Darkfield, part of Orizon, says the case was treated as a data leak and that the total volume exposed, as well as the encryption details, have not yet been publicly quantified.

The Judiciary of Jujuy Province is listed as a confirmed victim of the Emperador ransomware group, after a compromise involving WordPress databases, internal system access credentials, and email credentials. Darkfield, part of Orizon, describes the incident as a data leak and says the total volume of exposed information and the encryption details have not yet been publicly quantified.

What is known about Emperador?

Emperador is a financially motivated ransomware group first observed in August 2026, according to Darkfield. The same source places it in a documented focus on government and defense, with targets in the Philippines and at least one confirmed victim in Argentina.

That regional record also includes a case outside Latin America. Ransomware.live lists the Bosnia and Herzegovina Mine Action Center as a possible victim of the operation, but says it is an emerging group and that claim should be treated cautiously until independently verified.

What scope do the attributed cases show?

The available reports point to a pattern of data exposure rather than a simple systems encryption event. In Jujuy, Darkfield said credentials and database contents were accessed, while the Bosnia and Herzegovina case remains without independent confirmation.

Emperador’s activity still appears limited in terms of solid attribution, but it already has a presence in at least two different regions. For now, the Argentine case is the only confirmed one in Latin America in the information provided.

How does it compare with other active groups in the region?

The available threat intelligence points to a broader ransomware environment with heavy pressure on Latin America and APAC. In Asia-Pacific, Group-IB identified The Gentlemen and Krybit as especially active operators during August 2026.

Group-IB reported that The Gentlemen claimed 37 leak events in the region, while Krybit showed a month-over-month increase of about 230% across eight APAC countries, with a particularly strong impact on the healthcare sector. The same report places Krybit as a ransomware and data extortion group first documented in April 2026.

In Latin America, a regional analysis cited by Yahoo Noticias and based on SCILabs data said The Gentlemen became the most active variant, with at least 49 recorded attacks, followed by Qilin with 46 and LockBit 5.0 with 43. Krybit added 12 cases in the region, according to the same review.

The Gentlemen also expanded its footprint in the region with claims against other organizations. Galaxy Warden said the group claimed to have obtained personal and financial data, emails, and infrastructure details from AbacoViaggi, and more than 3.5 million patient records from Veradigm, with neither company publicly confirming those claims at the time of those analyses.

TechWalrus, meanwhile, reported that The Gentlemen claimed to have compromised Lider Aviação, one of the largest business aviation operators in Brazil and Latin America, starting on September 5, 2026, according to Ransomware.live tracking, although no data samples or technical details of the intrusion vector were published. FortiGuard Labs added that the group’s leak site had listed more than 200 victim organizations in over 50 countries by early 2026.

In that same regional review, Yahoo Noticias also said The Gentlemen began operating publicly in 2025 and added a tool called GentleKiller in 2026, designed to disable detection platforms installed on victim machines.

Sources

View all