Brazil's tax agency appears on a young crew's leak site

Published

An extortion crew called Emperador has put Receita Federal do Brasil, the country's federal tax and customs authority, on its data-leak site. The listing, recorded by the tracker ransomware.live on 23 September 2026, says the group took 6.3 GB covering "several thousand documents with personnel and customer data, as well as all user data on gov.br with passwords." gov.br is the federal government's single sign-on portal.

None of that is confirmed. It is a claim made by the people trying to extort the victim, and IntelFusions found no public statement from Receita Federal at the time of writing. The same caveat applies to every other listing described below.

A boast bigger than the file it comes with

The claim deserves scepticism on its own terms. A login system serving a national population is a very large dataset, and the crew's own figure for the whole haul is 6.3 GB, most of it described as documents. The posting offers no sample, record count or technical detail that would let an outsider test the gov.br part of the boast. Extortion crews routinely inflate what they hold to raise the pressure on a victim.

That does not make it harmless. Even a partial set of staff records from a tax authority is useful to fraudsters, and a public claim naming gov.br is itself an invitation for phishing campaigns that impersonate a "security reset" of the portal. Brazilians should treat any unsolicited message about their gov.br account with extra suspicion for the next few weeks and sign in only by typing the address themselves.

Third Brazilian public body on one crew's list

The Receita Federal entry is the third time Emperador has listed a Brazilian government body since its leak site went live in mid-August. IntelFusions data shows it named the Prefeitura Municipal de Arcos, a municipality in Minas Gerais, on 18 August, and an entry it labels "Cassias MG Government" on 19 September (MG is the state abbreviation for Minas Gerais). Across all countries, the Emperador leak site has carried 27 claims in our tracking since its first listing on 12 August, and six of them are public bodies:

More than one claim in five going to government is a high share for a crew this young, and half of those government claims are Brazilian. We covered the Jujuy court listing in our earlier look at South America's leak sites. Emperador is not the only crew doing this: The Gentlemen listed the Municipal Chamber of Serra and an entry titled "Intranet Gov Brasil" in late July and early August, bringing Brazil's government listings to five in 90 days.

Brazil's leak-site volume is creeping up

Across all crews, Brazilian organizations appeared in 27 leak-site claims in the last 30 days, up from 22 in the 30 days before. That is a modest rise, not a surge; the government listings are what stand out. Brazil's public sector has already been a target this month for other reasons too, including the hijacking of government websites to rig search results. Our Brazil country profile tracks the wider picture.

Check gov.br access now, not after a data dump

For Brazilian public bodies, the practical step is to treat this as a prompt rather than to wait for a leak. Review privileged and service accounts that touch gov.br integrations, force resets where access cannot be accounted for, and report suspected compromise to CERT.br.

A claim like this one is a pressure tactic before it is anything else. The question it raises for Brazil is not whether Emperador really holds every gov.br password, which is unlikely on the evidence published, but why a crew whose leak site is under seven weeks old keeps finding Brazilian public bodies worth naming.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions