Skip to content
Leak-site post naming Amazon Informatica, captured by ThreatCluster

Amazon Informatica

emperador

Ransomware leak-site victim intelligence · EN

Data size
110.0 MB
Views
653
Posted
Sep 28, 2026
Country
Brazil
Industry
Information Technology (IT) solutions integrator and managed services provider

Summary

Written by ThreatClusterfrom site fields, file listing, victim profile, leak post, screenshot, ransom note

The group emperador claims to have exfiltrated 110.0 MB of data from Amazon Informática LTDA, a Brazil-based IT solutions integrator and MSP. They state the data includes sensitive PII schemas, employee registries, banking credentials, and CPF and RG data. The leak post is published on the group’s site.

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

Victim profile

Founded
1995
Domains
https://amazoninformatica.com.br/

What was taken

For Sale Amazon Informatica $5,000 Amazon Informática LTDA is a prominent Information Technology (IT) solutions integrator and managed services provider founded in Brazil in 1995. Amazon Informática's primary market focus is the public sector and government agencies, serving various state and federal entities in Brazil.To support these operations, they maintain strategic corporate offices in Brasília/DF (to service the federal government cluster) and Belém/PA. Furthermore, the company has expanded its footprint internationally with operational branches in Latin America and Europe (Portugal), where they deliver customized government tech solutions and enterprise infrastructure support to large private corporations in those regions.

Data categories
sensitive PII schemasemployee registriesbanking credentialsCPFRG data

Ransom note

Published by the group on their leak site, reproduced verbatim.

Full commitment of the network having full access to infrastructure, thus ensuring full access to the databases containing confidential and financial information!

Also stated on the leak page

Fields this group publishes that do not map to a standard column. Labels are the site's own.

TOX ID
3D6EF83C3C4517FE42B212A934D4B08579A5F20522828C4E4818EA117F53063377C4D769640B
SESSION
052a5fe97f7b1822c2225ba884b5f719c07ec99da7d838421a20958938f54cb539

Leak-site images (4)

Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.

ThreatCluster capture
The image features a stylized red logo with angular shapes resembling a hooded figure or mask.
onion leak page1.2 MB
Screenshot of a text document containing email correspondence and service request details, including contact information and instructions for further action.
onion leak page454 KB
Screenshot of a system information report displaying hardware and network details, including CPU, memory, and network adapters.
onion leak page419 KB

Negotiation

Tox 3D6EF83C3C4517FE42B212A934D4B08579A5F20522828C4E4818EA117F53063377C4D769640B