emperadorRansomware VictimManufacturing

Electrolux & Ontrac

Hello Electrolux & OnTrac, Still no response from you. When we called your IT helpdesk posing as threat researchers and asked about the breach, we were told, "We cannot talk about it." You have one week before we release more data - starting with information on your employees. We'd prefer to settle this directly. Same goes for OnTrac. We recently learned that OnTrac has been paying employees as little as $14.50 an hour. As a result, we will be releasing salary information for all of their employees. I also managed to get in touch with a former OnTrac employee, chill guy. Said his time there was horrible. EMAIL: xdlmfao@morke.ru SESSION: 05651c7323273b723588d47455471ee9e27feb5187a30f2933554a705aacb38358 [Sector: Retail, Manufacturing, Transportation]

Incident Details

Threat Group
emperador
Victim / Organization
Electrolux & Ontrac
Website / Domain
—
Industry Sector
Manufacturing
Country / Region
—
Date Discovered
Friday, September 25, 2026

What This Listing Means

Posting on emperador's ransomware leak site typically signals that the threat actor claims to have:

  • ▸Gained unauthorized access to the organization's network via phishing, exposed credentials, or an unpatched vulnerability
  • ▸Exfiltrated sensitive data — potentially including financial records, PII, customer data, or trade secrets
  • ▸Deployed ransomware to encrypt systems and disrupt operations
  • ▸Issued a ransom demand with a deadline to publish all stolen data publicly if unpaid

Open Source Investigation

Is This Your Organization?

Security Arsenal provides 24/7 ransomware incident response. We contain active attacks, support ransom negotiation decisions, perform forensic analysis, and recover your data.

Get Emergency ResponseIR Services Overview

Protect Your Organization

← Back to Ransomware Tracker