Quick Summary
AllegedExecutive Summary
Ample Surveyor Services Limited, a business services company based in the United States, was identified as a victim by the DragonForce ransomware group on July 7, 2026. This listing was discovered through SOCRadar’s Dark Web Monitoring service. DragonForce has been notably active, claiming numerous victims in recent months, with a particular focus on the business services, manufacturing, and technology sectors. Geographically, their targets are predominantly located in the United States, the United Kingdom, and Germany. Ample Surveyor Services Limited aligns with DragonForce’s observed targeting patterns.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed significant credential exposure related to the amplesurveyor.com domain. This exposure included eight corporate credentials for organizational SaaS platforms like Box and Zoom, along with one credential for a third-party service. This indicates a direct exposure of employee credentials, likely originating from a stealer-infected endpoint, rather than a leak of customer data. The presence of corporate SaaS accounts suggests a high likelihood of corporate intrusion. Historically, infostealer-harvested credentials are a common initial access vector for ransomware operations like DragonForce. Threat intelligence teams are advised to prioritize credential rotation, session invalidation, and review of SaaS sign-in activity for the exposed accounts.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.