Quick Summary
AllegedExecutive Summary
Emperador listed Ipro.com, operating under the Reveal Data brand (revealdata[.]com), on its dark web portal on August 27, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring service. Ipro provides enterprise eDiscovery and litigation support software to law firms, corporate legal departments, and government agencies, making it a custodian of privileged legal data for its clients. Emperador has been active across professional services and technology targets in the past 60 days. Recent listings include NetExam, Capitol Mechanics, FRUCASTRO SL, and Vietnam Electricity (EVNHANOI). Ipro stands out within this cohort: the organization’s role as a legal data custodian means any exposure of client data extends well beyond a single-entity incident into privilege and regulatory territory.
Technical Analysis
SOCRadar’s telemetry returned 11 corporate employee credentials for revealdata[.]com. These records target auth[.]reveal-global[.]com and enterprise[.]ipro[.]com, which are the organization’s own enterprise authentication portals. The freshness window for these credentials spans from June through August 2026, with the most recent records dated only weeks before Emperador’s listing. Active credentials found on the organization’s own enterprise authentication portal, harvested in the period directly preceding the listing, align with patterns indicative of credential-based initial access. For a legal technology provider whose clients’ privileged data may reside within its platform, the downstream scope of any data exposure is substantially broader than a standard enterprise incident, potentially impacting regulatory and privileged information.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.