logo

DragonForce Ransomware Operators Hint at Ties to Russian Federation

ID: 1c47d403-f5bd-5727-9dc2-7497dafce7c5

STIX ID: report--1c47d403-f5bd-5727-9dc2-7497dafce7c5

Feed Name: Halcyon Blog

Threat Score
75/100

Date Published: 2025-05-12

Date Updated: 2026-04-28

...
...

A reported ransomware attack by the group DragonForce forced a major UK retailer to suspend its click-and-collect service and is linked to other victims including Co-op (where member data was stolen). The group operates a white-label ransomware-as-a-service model, claims responsibility for 167 victims across 32 countries, and publicly warned affiliates not to target Russia or former Soviet states—an indication the gang may be serving Russian geopolitical interests as a proxy while continuing criminal extortion operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.