Emperador, an emerging ransomware group, has claimed responsibility for a major cyberattack on EVNHANOI, the Hanoi branch of Vietnam Electricity, the country largest state-owned power company. The attackers reported the breach on August 22, claiming to have exfiltrated over 300 gigabytes of sensitive data affecting millions of customers.
The stolen dataset reportedly contains 13.36 million rows of customer details, 6.99 million subscription records, 2.26 million account records, and additional miscellaneous data. The group stated that the price for the data is open to negotiation, a common tactic used to pressure victims into paying ransoms before the information appears on underground markets.
Critical Infrastructure Under Fire
Vietnam Electricity (EVN) is the backbone of the country energy grid, supplying power to nearly 100 million people. Its Hanoi subsidiary, EVNHANOI, serves the capital city and surrounding provinces. A breach of this magnitude raises serious national security concerns, as the compromised data includes personally identifiable information, billing records, and account credentials tied to millions of households.
The attack underscores the growing targeting of state-owned energy companies across Asia. Earlier this month, state-sponsored hackers were suspected in a cyberattack on the British Columbia government, demonstrating that critical infrastructure remains a prime target for both criminal and nation-state actors.
Energy utilities present attractive targets for ransomware operators because of the outsized operational and political pressure that comes with disrupting power supply. Even when the attack does not directly impact grid operations, the exposure of customer databases creates downstream risks including identity theft, targeted phishing campaigns, and regulatory penalties.
Ransomware in Southeast Asia
The Emperador group has appeared in several recent ransomware claims across different sectors. The attack on EVNHANOI follows a pattern of increasingly bold campaigns targeting government-linked entities in Southeast Asia, where cybersecurity investment and incident response maturity often lag behind Western counterparts.
Authorities in Vietnam have not publicly confirmed the breach. Cybersecurity firms have urged EVN to conduct a full compromise assessment and notify affected customers. With 300GB of data in potential circulation, the downstream impact could be significant if the information reaches threat actor forums.
discussion