← Blog

EVNHANOI Claim: Emperador Cites 13.36M Rows

Share on X

Unverified claim — August 22, 2026: Leak trackers report that ransomware brand Emperador listed Vietnam Electricity / EVNHANOI (evn.com.vn) and advertised more than 300GB of data, including about 13.36 million rows of customer details, 6.99 million subscriptions, and 2.26 million account records, with price “open to negotiation.” EVN had not confirmed at indexing. Canonical row: evnhanoi-emperador2026. Source overview: DeXpose summary.

Power utilities sit in a different risk class than e-commerce shops. Customer master data at national-electric scale is billing identity, meter linkage, and household location by another name — even when the leak post never mentions outages.

Treat every figure below as an actor-attested, unverified claim until EVN or Vietnamese authorities publish a matching notice.

What the Emperador EVNHANOI claim says

According to the August 22 tracker write-up, Emperador’s listing names Vietnam Electricity (EVNHANOI), points at evn.com.vn, and pitches a corpus “exceeding 300GB” with the row counts above. No independent journalist had authenticated a full dump at indexing. No sample field dictionary beyond “customer details / subscriptions / account records” was reproduced in the secondary summary BreachHistory reviewed.

Why this claim is high-signal while unverified

  • Critical infrastructure victim — electricity distribution for Hanoi / EVN’s public footprint.
  • Census-class actor math — 13 million customer-detail rows is population-adjacent for a metro utility.
  • Named ransomware brand + named org + concrete volume — enough to index under BreachHistory’s 2026 leak-site policy, labeled unverified.

What we do not know

Intrusion path, whether OT/SCADA was touched, whether billing databases or office file shares dominate the 300GB, and whether “13.36 million rows” means unique households or duplicated extracts. EVN silence is not confirmation. BreachHistory sets recordsAffected to 13360000 as the actor customer-detail floor and keeps companyConfirmed: false.

Who would be at risk if the dump is real

Hanoi-area residential and commercial electricity customers whose names, addresses, meter or account identifiers, and subscription status appear in billing systems. Employees and contractors in the account tables. Collections and call-center workflows that use the same IDs for knowledge-based authentication. Even customers who moved last year may remain in historical extracts.

Fraud and outage-phishing context

Utility breaches fuel “pay your overdue bill or we disconnect tonight” SMS with accurate account fragments. They also fuel fake EVN apps and QR payment pages. A 300GB marketing claim is enough for criminals who never touch the real dump to ride the headline.

Related Vietnam and infrastructure context

BreachHistory already tracks other Vietnam-linked claims such as the Vietnam MoH staff listing write-up. Do not merge health-ministry and electricity-utility rows. Separately, 2026 industrial claims against names like Shell and GE show how fast critical-sector leak posts travel — each still needs its own evidence bar.

What EVN and regulators have said

As of indexing on August 23, 2026, no matching EVN English press release confirming Emperador’s numbers was located in sources reviewed. Watch EVN / EVNHANOI official channels, Vietnam’s cybersecurity authority notices, and reputable trade press citing named confirmation.

Action items

  1. Ignore SMS that threaten immediate power cutoffs and demand card payment via shortened links.
  2. Pay bills only through official EVN apps or known bank transfer references you already use.
  3. If a caller cites your exact account number “because of the Emperador leak,” hang up and redial the printed hotline on a prior bill.
  4. Employees: treat unexpected MFA resets on EVN corporate mail as hostile.
  5. Do not download alleged 300GB utility dumps from forums.
  6. Small businesses: verify any “grid upgrade fee” invoice out-of-band.
  7. Keep the tracker URL for chronology; do not treat aggregator mirrors as primary proof.
  8. If EVN later mails customers, trust the domain on the letter — not a QR in a Facebook comment.

Canonical record

evnhanoi-emperador2026 — unverified Emperador claim; 13,360,000 actor customer-detail rows; companyConfirmed false. Updates follow primary confirmation only.

Bottom line for readers searching “EVN data breach 2026” or “EVNHANOI ransomware”: unverified Emperador listing, huge actor counts, critical-infrastructure victim, no company confirmation at indexing. Prepare for bill-scam phishing either way; do not treat 13.36 million as a census until EVN speaks.

Foreign investors and factories on EVN feeders should ask facilities teams whether vendor portals share the same identity store as retail billing. Ransomware crews love the office network that happens to sit beside customer extracts.

Journalists should demand sample authentication before repeating “millions of Vietnam electricity customers confirmed breached.” Actor PDFs are marketing. Confirmation is a utility notice or regulator filing.

If the listing is recycled or inflated, EVN’s denial will collapse the story quickly. If it is real, notification logistics for 13 million rows will take weeks. Harden payment habits now.

Neighboring households often share Wi-Fi and bill-pay apps. Brief family members who handle elderly relatives’ electricity accounts — they are prime voice-phishing targets after a utility headline.

Compare this claim’s stakes to consumer SaaS leaks: losing a streaming password is annoying; losing a meter-linked national ID pattern can become a year of believable government-adjacent fraud. That is why BreachHistory indexes named utility leak-site posts even before confirmation.

Security vendors selling “EVN dark web monitoring” off an unverified post should be treated skeptically. Paid panic is a secondary industry around every ransomware headline.

For defenders inside ASEAN utilities: tabletop a leak-site post that cites your exact customer-row counts. Your communications team will need a holding statement before legal finishes forensics.

Researchers comparing Emperador’s portfolio to other 2026 brands should track naming consistency and whether EVN appears on multiple leak sites — multi-posting is common and still not proof.

Until EVN confirms or denies, the accurate public sentence is: Emperador claims a massive EVNHANOI customer/account corpus; independent confirmation is pending; customers should harden bill-pay channels and distrust cutoff threats.

Diaspora Vietnamese who still hold Hanoi residential accounts should watch relatives’ phones for bilingual scam calls that mix English breach news with Vietnamese account trivia.

Finally, do not confuse EVNHANOI with unrelated “Vietnam power” forum dumps that lack a named operator and volume breakdown. Named victim plus actor counts is the indexing bar used here.

Share the canonical BreachHistory link when correcting viral posts that invent outages or SCADA meltdowns the Emperador marketing text never evidenced.

If confirmation arrives with a smaller attested count, the catalog row will move with it. Actor floors are not sacred — primary sources are.

One more practical note: photograph your latest paper bill (account number visible only to you). Phishing kits invent account formats; having the real layout offline helps spot fakes.

Why utility customer tables differ from “another SaaS leak”

Electricity accounts are sticky. People change email hosts and shopping sites; they rarely change the utility that lights their kitchen. That stickiness makes a claimed 13-million-row customer extract valuable years after the intrusion date — if the intrusion is real. It also means phishing can reference seasons of usage or neighborhood feeder language that feels intimate.

Subscriptions and account records, as Emperador’s marketing splits them, may include dormant or closed accounts. Dormant does not mean harmless. Re-activation scams thrive on “we found your old EVN account in the breach — verify to keep it clean” scripts.

National energy security vs. office IT

Headlines will jump to blackouts. The Emperador text BreachHistory reviewed emphasizes customer and account corpora, not turbine firmware. Those are different failure modes. A billing-data extortion event can be catastrophic for privacy and fraud without ever flipping a breaker. Conversely, absence of outage evidence does not prove the listing is fake — office estates and customer databases are frequent ransomware prizes precisely because they are softer than OT.

Readers should hold two thoughts: (1) unverified marketing may exaggerate; (2) even a partial customer extract from a capital-city utility is a high-impact privacy event.

How BreachHistory will update this row

Confirmation, denial, or a regulator-attested count will rewrite evnhanoi-emperador2026. A smaller confirmed census beats a larger actor boast. Additional leak mirrors that only copy DeXpose wording without new evidence will not, alone, flip companyConfirmed.

If EVN publishes a narrow statement — “we are investigating reports” — that is still not a confirmation of 13.36 million rows. Watch for field lists, date ranges, and whether residential and commercial books were both in scope.

Sector playbook for other ASEAN utilities

Assume a leak site will eventually name you. Pre-draft customer SMS that do not include clickable payment links. Pre-stage call-center macros that refuse to discuss “the ransomware article” over the phone beyond directing callers to a printed hotline. Segment retail billing extracts from corporate Active Directory so one office compromise cannot ship every meter in the capital.

Meter-to-person linkage is the crown jewel. If your data warehouse denormalizes national ID, phone, and meter ID into one wide table for “analytics convenience,” you have already written the attacker’s SELECT list.

Community organizers in Hanoi apartment blocks can help by posting one official EVN URL on building notice boards — and explicitly listing the fake domains circulating that week. Accuracy beats volume in rumor control.

English-language tech Twitter will amplify the 300GB number because it is round and scary. Amplify the unverified label just as loudly. Scale claims without confirmation are how dump-resellers advertise.

If you are a journalist with a sample, authenticate against live customer service flows carefully and ethically — never publish raw rows with names and meter numbers. Describe schema, not people.

Closedown line for search: EVNHANOI Emperador claim, August 22, 2026, ~13.36M customer-detail rows alleged, 300GB alleged, no EVN confirmation at BreachHistory indexing, canonical catalog link above, practical defense is bill-pay hygiene and cutoff-scam skepticism.

Procurement teams renewing AMI / smart-meter contracts should add contractual language requiring encryption of customer PII at rest in analytics lakes and forbidding flat-file exports to vendor laptops. Emperador-style claims often trace to boring office compromise plus a warehouse full of CSV, not a Hollywood breaker room scene.

University researchers studying Vietnam’s digital infrastructure should avoid mirroring alleged dumps into academic object storage “for science.” That creates a second exposure event. Aggregate statistics and redacted schemas suffice for papers.

Call-center BPO partners handling EVN overflow should rotate social-engineering drills this month: callers who cite “Emperador” and demand account unlocks. Reward agents who refuse and escalate — not agents who “just help quickly.”

If you already paid a suspicious “reconnection fee” after seeing this headline, contact your bank’s fraud desk the same day. Speed matters more than embarrassment. Then tell relatives so the same kit fails twice.

Regional CERTs watching ASEAN utility noise should correlate Emperador’s EVNHANOI post with any concurrent credential-market chatter for evn.com.vn mailboxes. Infostealer logs sometimes precede leak-site theater by weeks; sometimes the theater is empty.

BreachHistory’s job here is narrow: name the victim, label the claim unverified, publish the actor counts as actor counts, and give customers something useful to do before confirmation arrives. That is this page.

Last check for skimmers: the title says claim; the excerpt says unverified; the opening paragraph says unverified. If a repost strips those words, you are reading marketing, not reporting.

Factory parks and industrial zones billed through EVN commercial tariffs should designate a single employee who validates any “emergency grid fee” email by phone using a pre-written vendor contact sheet — not the reply-to on the suspicious message. Finance teams that rubber-stamp urgent utility PDFs will fund the attackers twice: once via extortion theater, once via invoice fraud.

Parents paying household bills for student apartments in Hanoi should warn kids that Discord “leak lookup bots” asking for an account number plus national ID are harvesting, not helping. Curiosity is the second infection vector after the original claim.

When Vietnamese-language television covers the rumor, expect a same-day spike in fake EVN Facebook pages. Report them; do not argue in comments with your meter number as a flex.

Unverified does not mean unimportant. It means the honest sentence still needs the label. Keep the label until EVN or a regulator takes it off.

Landlords who collect electricity reimbursements from tenants should stop accepting screenshot “EVN QR codes” forwarded on Zalo without checking the merchant name on a known bill. Group-chat payment theater scales faster than any utility press office.

IT auditors reviewing EVN suppliers this quarter should ask for evidence of egress controls on databases that join meter IDs to national IDs — and for a tested customer-notification runbook measured in days, not months. Leak-site math waits for no change-control board.

If you only remember three words from this page, make them: unverified, official channels, no SMS links.

Municipalities that resell or co-brand EVN payment points should audit which staff can export customer lists to spreadsheets. Insider-path copies often surface on the same forums as ransomware brands, with or without Emperador’s logo on the sales thread.

Stay with primary sources. Actor counts are a lead. Utility confirmation is the story. Until that confirmation arrives, treat every “full EVN dump” download link as malware advertising.

Enterprise customers with dedicated EVN account managers should insist on written guidance before changing any bank details on file. Callback verification beats chat-app urgency every time a ransomware brand trends.

This page will age well only if the unverified label stays visible. Keep it visible. If EVN confirms tomorrow, celebrate the clarity — and still keep paying through official channels only. Curiosity clicks are how secondary scams win after every unverified utility headline online today.