Quick Summary
AllegedExecutive Summary
Petrini Valores, a financial services company based in Argentina, has been listed as a victim on the DragonForce ransomware group’s dark web portal, published on July 16, 2026. The listing was identified through SOCRadar’s Dark Web Monitoring service. Petrini Valores operates in the Financial Services sector. The entry places the organisation within DragonForce’s recent run of leak-site activity across multiple regions and sectors, suggesting a broad operational scope for the threat actor. In the 60 days prior to this listing, DragonForce had claimed 84 other victims. The group has frequently targeted the Business Services, Manufacturing, and Consumer Services sectors, with a notable concentration of victims in the United States, the United Kingdom, and Germany. Other recent DragonForce victims with similar profiles to Petrini Valores include Delbrook Capital Advisors, epbinsurance.com, TAURUS INVESTMENT HOLDINGS, and Nicholson y Cano Abogados. While Petrini Valores does not precisely match the group’s most common targets, this listing provides insight into the expanding victimology of DragonForce.
Technical Analysis
Initial-access correlation against SOCRadar’s stealer-log telemetry surfaced a notable exposure for the petrini.com.ar domain. The queried data returned three records associated with the organisation’s own domain and an administrative subdomain. These records utilized generic or system-style usernames, including a root-like account on an admin portal, rather than identifiable employee emails. The credential linked to the administrative subdomain is particularly significant as it suggests potential privileged access to internal infrastructure, despite the masked username preventing definitive attribution. The credential exposure window is noted to be long-tailed, spanning from December 2024 to March 2026, indicating that these credentials have persisted without rotation. For ransomware operators such as DragonForce, credentials harvested by infostealers represent a recognized initial access vector. Threat actors or initial access brokers commonly source fresh logs from underground marketplaces, validate the corporate credentials contained within them, and then use these to gain access to systems like Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the stealer-log evidence does not definitively confirm that these specific credentials were exploited by DragonForce, the observed pattern aligns with the typical attack chain associated with this type of incident. This exposure flags the compromised accounts and affected endpoints as priorities for immediate credential rotation and thorough security review.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.