Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

Threats, Incidents and Claims

DragonForce Ransomware: 638 Victims and How It Gets In

By the Assured Cyber Protection team · Updated 2026 · Reviewed

DragonForce ransomware is not a gang in the way most people picture one. It is a platform. The group builds the encryption software, the leak site and the negotiation infrastructure, then rents the lot to affiliates who do the breaking in and keep the larger share of whatever gets paid. That structure is the whole reason a name most UK business owners had never heard of in 2024 ended up attached to the worst run of retail cyber attacks this country has seen.

As of mid August 2026 its leak site listed 638 claimed victims, with the most recent added on 13 August. The group logged 253 claimed victims in the first half of 2026 alone, an average of roughly 28 to 30 a month. UK organisations appear in that list steadily rather than occasionally.

This page covers what the group actually is, how its affiliates get inside a network, and the specific controls that stop them, which are the same controls your insurer will ask about at renewal.

Where DragonForce came from

DragonForce emerged as a ransomware-as-a-service operation in 2023. Do not confuse it with DragonForce Malaysia, an unrelated hacktivist group with a similar name; the security industry has been sloppy about this and it has caused genuine confusion.

Its model has shifted twice. It began as conventional ransomware-as-a-service: affiliates use the encryptor, the operators take a cut. In 2025 it repositioned as a cartel, offering affiliates white-label branding so a crew could run its own apparent brand on DragonForce infrastructure. During the second quarter of 2026 it expanded that into what it calls RansomBay, with affiliates keeping around 80% of ransoms paid and the operators taking 20%.

Why this matters to a defender: you are not up against one group with one playbook. You are up against whoever rented the platform this month, and their skill level and tactics vary enormously. Two DragonForce incidents can look nothing alike.

The group also applies the usual Russian-speaking-ecosystem restriction of not attacking targets in CIS countries, which is a reasonable indicator of where its operators sit.

The UK retail wave, and what it actually cost

DragonForce became a household name in Britain over Easter 2025, when attacks on Marks and Spencer, Co-op and Harrods were claimed by people representing the operation. The affiliate work was linked to Scattered Spider, an English-speaking crew that specialises in talking its way past IT help desks rather than exploiting software.

The M&S case is the clearest example of how the two halves fit together. Intruders are understood to have been inside since February 2025. They obtained the NTDS.dit file, which holds the password hashes for every Windows account in the domain, cracked what they needed, moved through the domain, and on 24 April deployed white-label DragonForce ransomware against VMware ESXi hosts, taking out large numbers of virtual machines at once.

The financial damage was not subtle. M&S statutory profit fell from £391.4m the previous year to £3.4m. The UK’s Cyber Monitoring Centre classed the M&S and Co-op incidents together as a Category 2 event on its cyber hurricane scale, with total costs estimated between £270m and £440m.

We cover the incident timeline and the insurance response separately in cyber attacks on UK retailers and cyber insurance for retailers. What follows is the part that generalises to everyone else.

How affiliates get in

Across reported DragonForce cases the initial access falls into two buckets, and they need different defences.

Two ways in, one ending Route 1: the help desk Caller impersonates staff, gets a password or MFA reset Route 2: the edge Ivanti, Fortinet, SonicWall remote access appliances Disable the defences Vulnerable driver kills EDR Steal the data Leak site leverage Encrypt ESXi hosts Dozens of servers at once Neither route starts with malware. Both end with the same two actions. Sources: reported DragonForce incident analysis and NCSC guidance following the 2025 UK retail attacks. Diagram by Assured Cyber Protection.
Diagram by Assured Cyber Protection.

1. The help desk. The Scattered Spider style is a phone call. Someone rings your service desk claiming to be a staff member, often a senior one, locked out of their account, and talks the agent into resetting the password or, more damagingly, re-enrolling multi-factor authentication on a device the attacker controls. No malware, no exploit, no alert. After the retail attacks the NCSC specifically told organisations to review how their help desks verify a caller’s identity before resetting credentials, with extra care for senior and privileged accounts. Its broader guidance on mitigating malware and ransomware attacks is the reference to work through.

2. Internet-facing edge devices. Affiliates are consistently adept at attacking remote access infrastructure: Ivanti Connect Secure, Fortinet FortiOS and SonicWall SSL-VPN appliances feature repeatedly. These are the boxes that sit outside your firewall by definition, are often unpatched because patching them means downtime, and hand out network access when they fall.

Once inside, a recurring technique is bring your own vulnerable driver, where the attacker installs a legitimately signed but flawed driver in order to disable endpoint detection and antivirus from the kernel. Your EDR does not fail to spot the ransomware; it is switched off before the ransomware runs.

The May 2026 UK activity followed exactly this pattern, with seven UK companies claimed across the month, spanning professional services, tax advisory, logistics, heavy industry, a managed service provider and luxury retail. That MSP victim is the one to think hardest about: compromise a managed service provider and you inherit its client networks.

What actually stops it

Nothing here is exotic. All of it appears on cyber insurance proposal forms, and increasingly as a condition of cover.

Fix the help desk before you buy anything. Write down what an agent must verify before resetting a password or MFA factor, make it something an attacker cannot get from LinkedIn, and require a callback to a number already on file for privileged accounts. This costs nothing and closes the route that took down a FTSE 100 retailer.

Phishing-resistant MFA on remote access and admin accounts. SMS and push-approval codes can be talked out of people or fatigued into acceptance. Hardware keys and passkeys cannot. Note that Cyber Essentials tightened its MFA requirements in April 2026, which we cover in Cyber Essentials cost and the April 2026 MFA rule.

Treat edge devices as the emergency they are. Ivanti, Fortinet and SonicWall patches are not routine maintenance. Know every internet-facing appliance you own, subscribe to its vendor advisories, and patch out of hours the same week rather than the same quarter.

Turn on EDR tamper protection and alert on driver loads. If your endpoint tool can be uninstalled or stopped by a local administrator, it is decoration. Blocking known-vulnerable drivers and alerting when a new kernel driver loads catches the technique that precedes most encryption events.

Protect the hypervisor separately. Encrypting ESXi hosts is now standard practice because it destroys dozens of servers with one action. ESXi management interfaces should not be reachable from the general staff network, and hypervisor admin accounts should be separate from domain admin accounts.

Backups that survive the attacker having domain admin. Offline or immutable copies, tested restores, and a recovery time you have actually measured rather than estimated. Our RTO and RPO calculator is a starting point for working out whether your current arrangement matches what the business can tolerate.

Revoke sessions, not just passwords. After a suspected compromise, resetting a password leaves live tokens working. Full session revocation is the step commonly missed during a rushed response.

Watch outbound traffic. In a modern double-extortion attack the data leaves before anything is encrypted. Detecting the exfiltration is your last chance to act while the incident is still small. See endpoint security management and security incident and event management for how these fit together.

What it means for your insurance

Three practical points.

Insurers now underwrite on controls, not on sector alone. Help desk verification procedures, MFA type, EDR coverage and backup immutability are asked about directly, and answering optimistically on a proposal form is how claims get disputed later. A cyber security audit before renewal is cheaper than discovering the gap during a claim.

Business interruption is usually the bigger number, not the ransom. The M&S figures make this plain: the loss came from weeks of disrupted operations, not from a payment. If your policy limit was set around the cost of a ransom, it is set wrong. Our ransomware cost calculator gives you a rough total including downtime.

Data theft triggers separate obligations. DragonForce affiliates steal before they encrypt, so a UK organisation is likely facing an ICO notification decision inside 72 hours as well as a recovery operation. Know who makes that call before you need to.

Frequently asked questions

Is DragonForce ransomware still active in 2026? Yes. Its leak site listed 638 claimed victims as of mid August 2026, with new entries in August and 253 claimed in the first half of the year. UK organisations continue to appear on it.

Who is behind DragonForce ransomware? The operators run the platform and are believed to sit in the Russian-speaking cybercrime ecosystem, on the evidence that they avoid targets in CIS countries. The attacks themselves are carried out by affiliates who rent the platform, including English-speaking crews such as Scattered Spider. The name is unrelated to DragonForce Malaysia, a hacktivist group.

Should we pay a DragonForce ransom? That is a decision for your board with legal and incident response advice, and payment does not guarantee a working decryptor or the deletion of stolen data. If you hold cyber insurance, contact the insurer’s incident line before doing anything, because unauthorised payments can void cover. Also check sanctions exposure before any payment is considered.

Does cyber insurance cover a ransomware attack? Most UK cyber policies cover incident response, business interruption, data restoration and third-party liability, and many include extortion cover, subject to conditions. Cover increasingly depends on the controls you declared, particularly MFA and backups, so read the warranties rather than the summary.

What single change reduces the risk most? For most organisations, tightening how the IT help desk verifies identity before resetting a password or MFA factor. It is free, it takes an afternoon to write, and it closes the route used against the UK’s best-known victims.

How would we know if we had been breached? Rarely from the ransomware itself, which appears at the end. Earlier signals include unexpected MFA re-enrolments, new admin accounts, endpoint agents going offline, unfamiliar kernel drivers loading, and large outbound transfers to file-sharing services out of hours.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.