Jujuy Judiciary breach claim by Emperador
Emperador said it breached Jujuy’s judiciary and claimed 4.2 GB of data. There is no independent public confirmation.
The Emperador group said it compromised the judicial system of Jujuy province, Argentina, and stole data. The claim has circulated through monitoring sites and alert accounts, while RecentBreaches keeps it as an uncorroborated claim and TechWalrus said there is no public technical analysis detailing the scope.
The Emperador group said it compromised the judicial system of Jujuy province in Argentina and stole data. A secondary post attributes the claim to 4.2 GB of stolen information, along with WordPress credentials, access data, and email accounts. For now, the available evidence comes from monitoring sites and alert accounts, with no independent public confirmation from the agency.
What is known about the claim?
Emperador is said to have listed the case on Sept. 5, 2026, on a extortion site, according to RecentBreaches, which marks it as HIGH severity but classifies it as an uncorroborated claim. The same site says it found no public confirmation from the agency, regulators, or named media outlets about the incident.
The attribution was also repeated by a monitoring account on X, TweetThreatNews, which reported that ransomware had affected Jujuy’s judiciary and repeated the 4.2 GB figure. In the same vein, FalconFeeds.io posted an alert on X saying the Judicial Branch of the Province of Jujuy would have been hit by the EMPERADOR ransomware.
What do tracking sites say?
Darkfield, from Orizon, describes the case as a data leak attributed to Emperador in Argentina’s Government and Defense sector. It lists the status as "Data leaked," with critical severity, and references the exfiltration of judicial infrastructure that would include administrative credentials and court databases, with the group’s operation marked active.
The same portal adds context on Emperador. It places the group’s first observed activity in August 2026, says it appears financially motivated, notes that its operational history remains limited, and says its recorded focus is Government and Defense. It also states that its previous victims were concentrated in the Philippines.
Is there technical or official confirmation?
As of TechWalrus’ analysis, there was no public technical report detailing how the intrusion happened, which specific systems were affected, or what data may have been stolen. The outlet recommended following future official statements from the Judicial Branch of Jujuy to clarify the real scope of the incident.
RecentBreaches also keeps the Judicial Branch of the Province of Jujuy in its index with a single entry labeled "unconfirmed breach claim," attributed to September 2026. Taken together, those records leave the case, for now, as a claim attributed to Emperador rather than an official confirmation.
Sources
- Victim: Judicial Branch of the Province of Jujuy – emperadorransomware.live· ransomware.live
- Judicial Branch of the Province of Jujuy data breach — Emperador ransomware leak (2026)darkfield.orizon.one· Darkfield (Orizon)
- Cybersecurity News Everyday (@TweetThreatNews) on Xx.com· TweetThreatNews
- FalconFeeds.io on Xx.com· FalconFeeds.io
- Emperador ransomware claims Jujuy court system breachtechwalrus.com· TechWalrus
- Judicial Branch of the Province of Jujuy Ransomware Claim (2026) — What’s Alleged & Am I Affected?recentbreaches.com· RecentBreaches
- Judicial Branch of the Province of Jujuy: Unconfirmed Breach Claims & DoxxScan Ratingrecentbreaches.com· RecentBreaches



