RECEITA FEDERAL DO BRASIL Data Breach

Alleged

Ransomware claim involving RECEITA FEDERAL DO BRASIL

Published: Sep 23, 2026 Emperador
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
RECEITA FEDERAL DO BRASIL
Industry
Government & Defense
Threat Actor
Emperador
Date of Incident
Sep 23, 2026

Executive Summary

Emperador ransomware listed RECEITA FEDERAL DO BRASIL, Brazil’s federal revenue authority, on its dark web portal on September 23, 2026. This listing was identified through SOCRadar Dark Web Monitoring. Receita Federal is responsible for national tax collection, customs enforcement, and fiscal intelligence. This claim marks the most significant government institution targeted by the Emperador group to date. The Emperador group has claimed 24 other victims in the past 60 days, targeting sectors including Government & Defense, Manufacturing, and Professional Services. Their geographical focus includes Brazil, the United States, and Italy. Previously, Emperador has claimed responsibility for incidents involving entities like Cassias MG Government, Prefeitura Municipal de Arcos, Uniguacu, and the Bosnia and Herzegovina Mine Action Center. The inclusion of RECEITA FEDERAL DO BRASIL on their victim list is notably significant compared to their prior claims.

Technical Analysis

A query for the gov[.]br domain returned 11 records categorized as A (INTERNAL_AUTH_EMPLOYEE). It is important to note that gov.br is a shared Top-Level Domain utilized by numerous Brazilian entities, meaning these credentials cannot be definitively attributed solely to Receita Federal. The discovered records include endpoints for ADFS at agu.gov[.]br (Attorney General) and identity portals at contas.acesso.gov[.]br, which serves as Brazil’s unified citizen single sign-on service. If any of these records are associated with Receita Federal staff, there is a significant risk of authenticated lateral access across the shared Brazilian government infrastructure. The observed pattern is consistent with infostealer-to-ransomware kill chains that have been documented in previous government-sector incidents. However, the presence of these records in a stealer log does not confirm that Emperador has successfully utilized these credentials. The broad scope of the shared SSO environment also limits precise attribution. Consequently, the confidence level for stealer attribution is considered low. Despite this, if the credentials do indeed belong to Receita Federal staff, the operational risk is assessed as high due to the potential for compromised access. Recommended Actions: Immediate actions should include auditing access logs for agu.gov[.]br ADFS and contas.acesso.gov[.]br for any anomalous authentication activities. It is also recommended to force password resets on all gov.br-domain accounts currently in scope and to enforce Multi-Factor Authentication (MFA) on all Single Sign-On (SSO) endpoints. Incident response teams should be briefed on this potential threat.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.