Shocking Break‑In by the Ransomware Giant: DragonForce Hits New Targets

Listen to this Post

Featured Image

Introduction

At 00:51:34 UTC+3 on 13 November 2025, a cyber‑extortion alert rocked the digital world: the ransomware actor known as DragonForce claimed new victims—“Persians – Cortinas – Todos – Alfombrass”—on the dark web. According to the threat‑intelligence team at ThreatMon, the group added these organisations to their victim list. This incident sounds a clear alarm amid an already worsening global ransomware scenario.

the Incident

On the evening of 12 November 2025, a post in dark‑web chatter by DragonForce announced that the groups/entities “Persians – Cortinas – Todos – Alfombrass” had been compromised. The post indicated these organisations were now victims of DragonForce’s ransomware operations and are expected to face data encryption, leak threats or extortion demands. While the identities and specific industries of those four names remain unclear, the announcement follows an established pattern of this threat actor publicly naming victims to amplify pressure and compliance.
ThreatMon’s detection reflects broader activity by DragonForce, which has emerged as a formidable ransomware‑as‑a‑service (RaaS) group, enabling affiliates to deploy high‑impact attacks internationally. The modus operandi typically involves infiltration, data theft, encryption and then disclosure threats. In this case the rapid naming of victims may serve two ends: first, to warn other organisations of exposure; second, to torch‑light the victims to disrupt recovery and compel payment. The timing and public nature of the claim underscore the adversary’s confidence and scale.
Given DragonForce’s prior track record—spanning major retail, manufacturing and service‑sector incidents—the addition of these victims suggests the group is either broadening its target list geographically or entering new verticals. The public claim of “Persians – Cortinas – Todos – Alfombrass” may signal a chain of businesses (for example suppliers with Spanish names) or a fragmented conglomerate hit. Either way, the pattern is clear: this threat group continues to expand.

What Undercode Say:

Operational Maturity and Threat Landscape

DragonForce began surfacing around late 2023, quickly adopting the ransomware‑as‑a‑service model.

SoC Radar

+3

www.trendmicro.com

+3

Specops Software

+3

Their evolution from simpler ransomware forks into a promotional “cartel” offering deep affiliate integration reveals high operational maturity.

Quorum Cyber

+1

The implication: organisations must treat this actor as a near‑enterprise business rather than an ad‑hoc cybercriminal cell.
What signals this latest claim tells us: one, public naming of victims is an escalation in psychological pressure design. Two, the victim set (“Persians – Cortinas – Todos – Alfombrass”) suggests the group is comfortable striking in regions such as Spanish‑speaking markets or supplier chains—a possible diversification beyond their more publicised UK / European retail hits.

Risk Amplification

When a group publicly claims victims, the risk to those organisations multiplies: not only must they contend with operational disruption and ransom demands, they now face brand damage, leak exposure and regulatory scrutiny. For supply‑chain companies (as these names may hint at), the ripple effect can extend across multiple downstream partners.

Tactics Worth Noting

DragonForce is reported to use multi‑variant payloads, reuse leaked builder code (from LockBit and Conti), and provide affiliates with customised ransomware toolkits.

www.trendmicro.com

+1

They are adept at ambushing victims with data‑theft and/or encryption, often threatening leaks first as leverage. Organisations impacted often discover the attack after the fact via logs or ransom notes.

Darktrace

Why This Matters

The public naming of new victims on 13 November is more than just a press‑release style move—it’s a signal to the criminal ecosystem that DragonForce remains active, confident and expanding. For defenders this means: complacency is not an option. Even smaller or less visible organisations might now be in the cross‑hairs because of affiliate scalability.

What Organisations Should Do Now

Treat your backups and incident response plans as mission‑critical. The group can encrypt, leak, or both.

Ensure threat monitoring covers supply‑chain exposure; even if you aren’t directly named, your vendor might be.

Simulate breach drills that anticipate data‑steal‑then‑leak models (not just encryption).

Adopt supplier‑risk assessment protocols — if your partner is named, your risk multiplies.

Undercode’s Take

In short: this claim is less about the specific victim names (which remain cryptic) and more about signalling. DragonForce is telling the world: “We strike when and where we choose.” That means every target—from major retailer to regional supplier—should assume they could be next. The window to act isn’t after detection—it’s before infection.

Fact Checker Results

✅ Evidence confirms DragonForce uses RaaS model and has grown significantly since 2023.

intel471.com

+1

✅ The group publicly naming victims is consistent with their extortion strategy of signalling and pressure.
❌ The exact identities, industries or geographies of “Persians – Cortinas – Todos – Alfombrass” cannot be validated from open‑sources at this time.

Prediction

In the coming months we anticipate the following:

More claims of lesser‑known victims by DragonForce, as they widen their target set and experiment with supply‑chain fragmentation.

A likely increase in “double extortion” cases where two or more criminal affiliates target the same organisation to force payment.

Organisations in supplier networks or non‑core business units will increasingly become soft targets; despite lower profiles, they represent accessible entry‑points into larger networks.
Expect that the threat landscape will shift such that defender budgets must prioritise affiliate‑driven RaaS threats—not just bespoke, state‑level campaigns.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon