DragonForce Ransomware Attack on Belk: The Full Story Behind the Breach

Listen to this Post

Featured Image
In May 2025, the well-known ransomware group DragonForce claimed responsibility for a significant cyberattack against Belk, one of the largest department store chains in the United States. The attack, which occurred between May 7 and May 11, 2025, resulted in the theft of sensitive internal documents, including personal information like Social Security numbers and names. This breach has sparked a broader conversation about the evolving threat landscape in cybersecurity, particularly in relation to high-profile retailers.

What Happened During the Belk Attack?

Belk, a major U.S. department store chain founded in 1888, was targeted by the DragonForce ransomware group in May 2025. The attack compromised various corporate systems, stealing internal documents containing sensitive data. The stolen data reportedly includes 156 gigabytes worth of files, some of which hold personal details such as Social Security numbers and names.

The company discovered the breach on May 8, 2025, and immediately began working with third-party cybersecurity experts to assess the extent of the attack. In the breach notification sent to the New Hampshire Attorney General’s Office, Belk confirmed that the unauthorized third party gained access to certain corporate systems and internal data.

In response, Belk quickly initiated a comprehensive security protocol: restricting network access, resetting passwords, rebuilding affected systems, and enhancing monitoring. Although the company has not fully recovered, it is offering 12 months of free credit monitoring and identity restoration services to individuals whose information was compromised. Despite these efforts, the attack has left its mark, with the company’s website still unavailable at the time of writing.

What Undercode Says:

The DragonForce ransomware group is not new to high-profile cyberattacks. This group has been active since December 2023 and is known for targeting retail giants such as Marks & Spencer, Co-op, and Harrods in the UK. Their approach to cybercrime is particularly concerning, as they not only encrypt the data of their victims but also exfiltrate sensitive information.

The attack on Belk adds to an alarming trend of ransomware gangs escalating their tactics. DragonForce operates in a hybrid model, where it not only conducts direct attacks but also runs a cybercrime affiliate service, giving other cybercriminals access to its tools in exchange for a share of the ransom. Their Telegram and Discord channels further suggest that the group is primarily composed of English-speaking teenagers, which underscores the growing involvement of younger individuals in the cybercrime world.

What makes this attack especially concerning is the leak of stolen data on the Tor network, indicating that negotiations with the attackers may have broken down. This is a troubling development in the world of ransomware, as it suggests that even when companies comply with ransom demands, they may not be able to recover their data or prevent it from being leaked.

Belk’s response to the breach, which involved blocking known indicators of compromise and rebuilding affected systems, is indicative of how organizations are forced to become more resilient in the face of these attacks. While this is a positive step, it highlights a larger issue: cybersecurity is no longer just about prevention, but about response and recovery. The evolving tactics of ransomware groups like DragonForce make it clear that every organization must be prepared to deal with a breach — not if, but when.

Fact Checker Results:

✅ Confirmed Breach: Belk’s notification of the breach aligns with the data reported by DragonForce.
✅ Compromised Data: Social Security numbers and personal details were indeed accessed during the attack.
❌ Cybercrime Affiliate Program: Although the ransomware group is known for its affiliate model, the exact nature of its operations remains difficult to verify fully.

Prediction:

Given the growing trend of cybercriminal groups like DragonForce, it’s likely that we will see more high-profile ransomware attacks on large retail organizations. As these groups refine their tactics, companies may face increasingly sophisticated extortion demands. For Belk, recovery will take time, and their ongoing efforts to protect affected individuals will likely become a case study for best practices in managing cyberattacks.

References:

Reported By: securityaffairs.com
Extra Source Hub:
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin