« All news

Ransomware · notable victim

Extortion group Emperador claims an attack on Electrolux

A recently emerged extortion group, Emperador, listed Swedish manufacturer Electrolux among its victims on 28 September 2026. The claim is unverified, but it highlights the growing pressure on European manufacturing.

What happened

On 28 September 2026, the extortion group known as Emperador posted a claim against Electrolux, the Swedish household appliance manufacturer and one of the country's best-known industrial names, on its victim listing site.

The status of the information matters: this is a claim made by the group itself. As of today there is no independent confirmation of the incident, and no verified public detail about which systems might be affected, what kind of information could be involved, or whether systems were encrypted in addition to a possible data exfiltration.

Statements published by extortion groups should be treated as unverified material. These actors frequently overstate the scope of an intrusion, recycle data from third parties or from older incidents, or publish entries that are later removed without explanation.

Who the group is

Emperador is a recent arrival: its leak site began publishing on 10 August 2026. That short track record means there is not yet a solid body of public analysis on its specific techniques, tooling or initial access methods.

In practice, emerging groups tend to reuse well-known approaches from the extortion ecosystem: exploitation of unpatched internet-facing services, use of stolen or purchased valid credentials, VPN or remote desktop access without multi-factor authentication, and targeted phishing. In the absence of specific indicators, the sensible response is to harden those generic entry points.

What organisations can do

For an industrial company, the risk is not only the publication of information: unplanned downtime in a plant or across the supply chain carries an immediate cost.

Realistic, prioritisable measures include: inventory and urgently patch everything exposed to the internet (VPNs, remote access portals, file transfer systems); enforce phishing-resistant multi-factor authentication on remote access and privileged accounts; monitor for anomalous use of valid credentials and of legitimate remote administration tools; segment IT and production (OT) networks; maintain immutable backups and test restoration; and review supplier and subsidiary access.

Finally, it is worth preparing a communications plan and a contact channel with the regulator and with customers, so that you can respond with facts if a claim like this one concerns your organisation.

About the group: Emperador

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.