HackerFeeds
All ransomware incidents
A

Ransomware group emperador hits Amazon Informatica

MEDIUM
·Technology·BR·2026-09-28

Amazon Informatica — a technology target operating in BR has been listed by the emperador ransomware group on 2026-09-28. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationAmazon Informatica
Threat Group
emperador
SummaryAmazon Informática LTDA is a prominent Information Technology (IT) solutions integrator and managed services provider founded in Brazil in 1995. Amazon Informática's primary market focus is the public sector and government agencies, serving various state and federal entities in Brazil.To support these operations, they maintain strategic corporate offices in Brasília/DF (to service the federal government cluster) and Belém/PA. Furthermore, the company has expanded its footprint internationally with operational branches in Latin America and Europe (Portugal), where they deliver customized government tech solutions and enterprise infrastructure support to large private corporations in those regions. Full commitment of the network having full access to infrastructure, thus ensuring full access to the databases containing confidential and financial information! Virtual Infrastructure and Database Cluster with active administrative master credentials exposed in text clear inside get_bk.bat. Hosts compromised. The targets contain production and integration databases with sensitive PII schemas, employee registries, banking credentials, CPF, and RG data. TOX ID: 3D6EF83C3C4517FE42B212A934D4B08579A5F20522828C4E4818EA117F53063377C4D769640B SESSION: 052a5fe97f7b1822c2225ba884b5f719c07ec99da7d838421a20958938f54cb539 [Sector: Government, Technology]
Date of Breach2026-09-28
Discovery Date2026-09-28
RegionBR
Target Domain—
Business SectorTechnology
Severity
MEDIUM

Claim by emperador

Amazon Informática LTDA is a prominent Information Technology (IT) solutions integrator and managed services provider founded in Brazil in 1995. Amazon Informática's primary market focus is the public sector and government agencies, serving various state and federal entities in Brazil.To support these operations, they maintain strategic corporate offices in Brasília/DF (to service the federal government cluster) and Belém/PA. Furthermore, the company has expanded its footprint internationally with operational branches in Latin America and Europe (Portugal), where they deliver customized government tech solutions and enterprise infrastructure support to large private corporations in those regions. Full commitment of the network having full access to infrastructure, thus ensuring full access to the databases containing confidential and financial information! Virtual Infrastructure and Database Cluster with active administrative master credentials exposed in text clear inside get_bk.bat. Hosts compromised. The targets contain production and integration databases with sensitive PII schemas, employee registries, banking credentials, CPF, and RG data. TOX ID: 3D6EF83C3C4517FE42B212A934D4B08579A5F20522828C4E4818EA117F53063377C4D769640B SESSION: 052a5fe97f7b1822c2225ba884b5f719c07ec99da7d838421a20958938f54cb539 [Sector: Government, Technology]

Posted by the emperador threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Sources

Leak post (onion / Tor)

tor

http://emprdr4p7iwlhpky33tswt3k2qdeljyjcdpoysabudmmrz4z32laexad.onion/post/amazon-informatica/

Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.