Forces Data Breach

Alleged

Ransomware claim involving Forces.

Published: Jul 7, 2026 MedusaLocker
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Forces
Threat Actor
MedusaLocker
Date of Incident
Jul 7, 2026

Executive Summary

Forces, an organization based in Canada, has been listed as a victim on the MedusaLocker ransomware group’s dark web portal, published on July 7, 2026. This listing was identified through SOCRadar’s Dark Web Monitoring service. The organization’s specific sector is not detailed, but its domain resolves to a Canadian federal namespace.

Technical Analysis

SOCRadar’s stealer-log telemetry revealed a significant exposure for the forces.gc.ca domain, containing 20 credentials on target-owned public-facing portals and 5 corporate credentials on third-party SaaS services. This combination suggests potential external account compromise and endpoint compromise. For ransomware operations like MedusaLocker, infostealer-harvested credentials are a common initial access vector. Threat intelligence teams should prioritize credential rotation, session invalidation, and review of SaaS sign-in activity for exposed corporate accounts.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.