Quick Summary
AllegedExecutive Summary
EduSpa, a United States-based company operating within the hospitality sector, has been identified as a victim on the DragonForce ransomware group’s dark web portal. The listing, published on August 6, 2026, was detected by SOCRadar’s Dark Web Monitoring service. EduSpa manages a complex web presence with multiple subdomains dedicated to training, membership, and internal operations, suggesting a platform-oriented business model rather than a single-site entity. This organization was one of two new entries attributed to DragonForce on this date. Over the preceding 60 days before this listing, DragonForce had claimed 50 other victims on its leak site. The group exhibits a strong preference for targeting the business services, manufacturing, and hospitality industries. Their victim base is primarily located in the United States, the United Kingdom, and the United Arab Emirates. Notable recent victims whose profiles align with EduSpa’s, such as hospitality firms or U.S.-based organizations, include TUI China, Katathani Phuket Beach Resort, Primary Eye Care, and Mike Graham Heating And Air Conditioning. Given that hospitality is DragonForce’s third most frequently targeted industry and the group has consistently pursued victims in this sector across various regions, this listing is consistent with their established targeting patterns.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a significant exposure for the eduspa.com domain. The collected data contained twenty-five records, all pertaining to the organization’s primary domain or its subdomains, with no indicators of third-party services being compromised. These credentials encompass at least seven distinct internal subdomains involved in training, membership, and back-office functions. The records are classified as customer, supplier, or third-party accounts on EduSpa-owned systems, as the masked usernames do not map to a corporate email address. The timestamps for these records range from December 4, 2024, to July 29, 2026, with a notable concentration of twenty records from June and July 2026, suggesting both long-standing persistence and recent activity. The prevalent profile indicated by these credentials is the takeover of customer accounts and supplier-related risks. For ransomware operations like DragonForce, credentials harvested by infostealers are a recognized method for initial access. Threat actors or initial access brokers typically acquire fresh logs from underground marketplaces, validate corporate credentials, and then use them to gain access to systems such as Microsoft 365, VPNs, or remote access portals before initiating ransomware deployment. While the stealer-log data identified does not definitively confirm that DragonForce utilized these specific credentials, the extensive coverage of an organization’s internal subdomains with credentials dated shortly before a leak-site listing is a pattern that warrants treating every affected account with suspicion. It is recommended that threat intelligence teams prioritize a comprehensive rotation of credentials across all subdomains, rather than awaiting direct confirmation of compromise.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.