DragonForce

DragonForce — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

DragonForceConfidence: High

Ransomware

Motivation: Financial

3Attributed Breaches Circulating
HighAttribution Confidence
RansomwareActor Type

Overview

Claimed the 2025 attacks on UK retailers M&S, Harrods, and Co-op, having shifted toward a RaaS-style model using leaked ransomware codebases. May be absorbing affiliates from disrupted crews.

Tactics, Targeting & TTPs

Targeting: retail and enterprise. Notes: possible affiliate absorption from disrupted crews.

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation