DragonForce affiliates sustained a broad ransomware and extortion campaign against UK organizations in May 2026, publicly naming seven UK victims on the group’s Tor leak site and posting 22 victims globally in a single day, including four UK firms. Reported victims spanned professional services, finance, logistics, construction, technology, and luxury retail, underscoring the group’s opportunistic targeting rather than a focus on one vertical. Helix International drew particular concern because of its role as a managed service provider with medium, large, and Fortune 500 clients, raising the risk of downstream compromise across customer environments.
Public reporting and curated intrusion data tie DragonForce activity to exploitation of exposed remote access and internet-facing systems, including Ivanti Connect Secure, FortiOS, FortiProxy, SonicOS SSL-VPN, Apache Log4j, Microsoft SmartScreen, and SimpleHelp RMM vulnerabilities. Tooling observed in DragonForce-linked intrusions includes utilities for discovery, remote management, credential theft, defense evasion, LOLBAS abuse, and exfiltration, while affiliates have also been linked to BYOVD techniques to disable or bypass EDR and antivirus protections. Prior reporting further connected DragonForce affiliates attributed to Scattered Spider to attacks on major UK retailers including M&S, Co-op, and Harrods.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-27, DragonForce posted 22 victims globally on its leak site, including four UK firms. The reporting highlighted this as evidence of accelerating campaign activity.
A community incident report describes a DragonForce ransomware intrusion against a small UK organization in April 2025. The attackers reportedly used SimpleHelp and AnyDesk, deployed Cobalt Strike, abused PowerShell, stole Veeam credentials, used the KslD.sys BYOVD driver to disable Microsoft Defender protections, and exfiltrated data with Restic before ransomware execution.
Prior reporting cited in the references says affiliates attributed to Scattered Spider used DragonForce in attacks on major UK retailers including M&S, Co-op, and Harrods. The activity is anchored to June 2025 in the source content.
Throughout May 2026, DragonForce affiliates publicly claimed seven UK-based victims on their Tor leak site. The affected UK organizations spanned sectors including professional services, finance, logistics, construction, technology, and luxury retail.
Reporting describes DragonForce as an opportunistic ransomware-as-a-service threat actor that has been active since late 2023. Affiliates commonly exploit exposed remote access infrastructure and compromised credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceransomware.live
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceblog.bushidotoken.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.