The DragonForce ransomware group has publicly claimed a series of attacks, demonstrating its continued activity across multiple sectors and geographies. On May 25, 2026, the group listed Saver NV, a major Dutch waste management company, as a victim on its data leak site, threatening to release stolen data. Concurrently, the group added two U.S. companies, BusinessRecord.com and Goldklang Group CPAs, to its victim list. These incidents underscore the persistent threat from ransomware operators who employ a double-extortion strategy of encrypting data and threatening to publish it.
DragonForce is a ransomware-as-a-service (RaaS) operation that follows a typical double-extortion model. Their attacks involve:
The attack on Saver NV, a critical infrastructure-adjacent entity, is particularly concerning. The simultaneous claims against a media outlet and an accounting firm in the U.S. show that the group is opportunistic and not limited to a single industry.
While the specific initial access vectors for these attacks were not disclosed, DragonForce and similar ransomware groups commonly use a range of TTPs to infiltrate networks.
T1486 - Data Encrypted for Impact: The core of the ransomware attack, rendering files unusable.T1657 - Exfiltration Over C2 Channel or T1567 - Exfiltration Over Web Service: The 'double extortion' tactic requires exfiltrating data before encryption.T1078 - Valid Accounts: Often used for initial access and lateral movement if credentials are stolen.T1190 - Exploit Public-Facing Application: A common initial access vector for ransomware groups.For the victims, the impact is severe. Saver NV faces operational disruption in the critical waste management sector and the threat of a sensitive data leak. BusinessRecord.com and Goldklang Group CPAs face similar threats of data exposure, which could include subscriber information, financial records, and client data, leading to significant reputational damage and regulatory penalties. All victims must contend with the high costs of incident response, business downtime, and potential ransom payments.
No specific technical indicators of compromise (IPs, hashes, domains) were provided in the source articles.
While this doesn't prevent encryption by attackers, having data-at-rest encryption can add a layer of complexity. The most important mitigation is having robust, offline backups.
Proper network segmentation can contain a ransomware infection, preventing it from spreading from a compromised workstation to critical servers or backup systems.
Ransomware groups frequently gain initial access by exploiting known vulnerabilities. A strong patch management program is a critical preventative measure.
DragonForce posts an extortion notice against Saver NV and lists two US firms as victims on its data leak site.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.