Skip to content
Leak-site post naming NetExam, captured by ThreatCluster

NetExam

emperador

Ransomware leak-site victim intelligence

Data size
18.1 MB
Files
5
Views
12,914
Posted
Aug 20, 2026
Country
United States
Industry
Technology

Summary

Written by ThreatClusterfrom file listing, victim profile, leak post, screenshot

The group emperador claims 18.1 MB of NetExam data across five CSV files, with sample filenames including tblUserDetail_.csv, tblUserLogOut.csv, tblCompany.csv, tblFailedSSOLogins.csv, and tblInvalidLogins.csv. The victim is NetExam (netexam.com), a US-based SaaS learning management system headquartered in Dallas. The leak post is published.

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

What was taken

NetExam (netexam.com) — the website of NetExam LMS+, a US-based SaaS learning management system built for external audiences rather than internal employees. It helps companies train, certify, and enable their channel partners, customers, and association members, with features like certification tracking, self-paced and instructor-led courses, e-commerce, white-labeling, Salesforce integration, and AI-powered course authoring agents. Headquartered in Dallas, with clients including AMD, AT&T, Oracle, Trellix, and Sabre. 18.1 MB as the sample.

File types seen
csv × 5
Sample files (5)
tblUserDetail_.csv
tblUserLogOut.csv
tblCompany.csv
tblFailedSSOLogins.csv
tblInvalidLogins.csv

Leak-site images (1)

Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.

ThreatCluster capture