Quick Summary
AllegedExecutive Summary
HIVE360, a technology company based in the United Kingdom specializing in payroll and employment services technology, has been identified as a victim of the DragonForce ransomware group. The listing appeared on the group’s dark web portal on July 7, 2026, as reported by SOCRadar’s Dark Web Monitoring service. This incident places HIVE360 within the group’s typical targeting profile, which includes the business services, manufacturing, and technology sectors, with a geographical focus on the United States, the United Kingdom, and Germany. DragonForce has been an active ransomware operation in the period leading up to this listing, claiming numerous victims. The group’s modus operandi often involves obtaining initial access through compromised credentials sourced from stealer logs. This specific case may involve the exposure of external portal accounts, rather than a direct corporate network compromise, as suggested by initial analysis of stealer-log telemetry.
Technical Analysis
SOCRadar’s analysis identified a potential initial access vector for HIVE360 through the exposure of credentials on the dark web. Analysis of stealer-log telemetry revealed 25 credentials for HIVE360’s external-facing portal, with one account repeatedly appearing, indicating persistent exposure. However, these exposed credentials were for external portal accounts and did not appear to be high-value identity, mail, or VPN endpoints. This type of exposure is consistent with the common initial access methods employed by ransomware groups like DragonForce, who often leverage infostealer-harvested credentials to gain entry into corporate systems. While this specific finding does not directly confirm a corporate compromise or link the credentials to the DragonForce listing, it serves as a strong indicator for CTI teams to review corporate credential hygiene and bolster account-takeover defenses on customer-facing portals. The threat actor’s profile aligns with HIVE360’s industry and location, reinforcing the potential relevance of this listing.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.