Judicial Branch of the Province of Jujuy Data Breach

Alleged

Ransomware claim involving Judicial Branch of the Province of Jujuy.

Published: Sep 5, 2026 Emperador
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Judicial Branch of the Province of Jujuy
Industry
Government
Threat Actor
Emperador
Date of Incident
Sep 5, 2026

Executive Summary

The Judicial Branch of the Province of Jujuy, an entity responsible for managing court records, case files, witness information, and legal proceedings in Argentina’s northwest, was listed on the emperador ransomware group’s dark web portal on September 5, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring service. While located in a less prominent financial region, the judiciary’s sensitive data, including witness information and ongoing criminal proceedings, presents significant risks beyond financial harm. In the preceding 60 days, emperador has claimed 11 other victims across the Government & Defense, Energy & Utilities, and Technology sectors. Their operations show a concentration in Latin America, with Brazil and Argentina being key targets. Recent victims attributed to emperador include Prefeitura Municipal de Arcos, City Government of Baguio, Uniguacu, and Hanwha Renewables. The targeting of the Jujuy judiciary further highlights the group’s sustained focus on public institutions within Argentina.

Technical Analysis

SOCRadar’s query into stealer-log data for justiciajujuy[.]gov.ar yielded no matching records. It is crucial to note that a lack of records from a single-domain query does not confirm the absence of compromise. Government entities often utilize a complex network of subdomains and diverse identity management systems, meaning credentials could exist under different corporate domains or through personal email aliases used for remote access. The absence of evidence in this specific stealer-log query does not rule out the possibility of credential compromise. Information harvested by infostealers can provide threat actors with initial access, enabling ransomware deployment and further network exploitation. Therefore, expanded monitoring across the broader judicial infrastructure of the Province of Jujuy is strongly recommended to ensure comprehensive security visibility.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.