Ransomware dossier

DragonForce

Runs a “cartel” affiliate model; linked to the 2025 wave of UK retail attacks.

Claimed victims

318

Top region

US

Top sector

Manufacturing

Suspected origin

Unattributed

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2026-09-24winfashionRetail & E-Commerce—
2026-09-24Arizona Vascular Medical Equipment, IncHealthcareUS
2026-09-24BMGP GroupeOtherFR
2026-09-24Elite Industech Co., LtdManufacturingTH
2026-09-24HEC GroupOtherTW
2026-09-20arsrenacer.comOtherAR
2026-09-16Community Property ManagementOtherUS
2026-09-16Owen Leigh OptometryHealthcareGB
2026-09-11Medical Department StoreRetail & E-CommerceUS
2026-09-06rubbermill.comManufacturingUS

Regions targeted

US 83GB 17DE 10CA 9CN 6AE 5HK 5IN 5

Sectors targeted

Manufacturing 37Professional Services 36Technology 20Healthcare 18Business Services 18Hospitality 10

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups