Quick Summary
AllegedExecutive Summary
GB Group S.A, a financial services organization based in Poland, has been listed as a victim on the DragonForce ransomware group’s dark web portal, with the listing published on August 13, 2026. This incident was identified through SOCRadar’s Dark Web Monitoring service. Operating within Poland’s financial services sector, GB Group S.A is involved in investment, capital, and financial management activities, managing a multinational employee base. The company’s corporate credential exposure spans various geographies, suggesting a broad operational footprint. DragonForce is an active ransomware-as-a-service operation known for consistently targeting mid-to-large enterprises across Europe and North America. In the 60 days leading up to this listing, DragonForce claimed 41 other victims. The group frequently targets the Business Services, Manufacturing, and Hospitality sectors, with a notable concentration of victims in the United States, the United Kingdom, and China. Recent DragonForce listings with overlaps in the financial or investment sector, or those representing European enterprises, include Petrini Valores, QPC Global, Primary Eye Care, and EduSpa. GB Group S.A’s inclusion slightly deviates from DragonForce’s typical victim geography, highlighting the group’s active targeting of Poland and the broader financial services sector.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry revealed a significant exposure for the gbgroup.com domain, with 25 records identified across multiple employees. This exposure included 5 records of credentials on organization-controlled systems, such as a corporate HR/identity portal (FlexHR), an internal network document appliance, and access via a Salesforce tenant. Additionally, 11 records of corporate usernames appeared on third-party SaaS platforms. High-value endpoints observed include an internal HR login portal accessed by three distinct corporate usernames over several months, an internal network appliance accessible from the same corporate account between February and June 2026, and an STS/identity broker used for cross-system authentication. The dominant credential profile identified was Mixed. Log dates range from February to August 2026, indicating a six-month window of active exposure, with the most recent records logged on August 9, 2026, just four days prior to the DragonForce listing. For ransomware groups like DragonForce, credentials harvested by infostealers serve as a common initial access vector. Operators or initial access brokers acquire fresh logs from underground marketplaces, validate corporate credentials, and subsequently use them to gain access to systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. While the stealer-log evidence does not definitively confirm that these specific credentials were exploited by DragonForce, the extent and recency of the exposure—which includes internal HR infrastructure, internal network appliances, and Salesforce tenants, with no apparent rotation over a six-month period—is consistent with the reconnaissance and credential validation phase that often precedes ransomware deployment. This multi-employee, multi-service exposure profile necessitates a comprehensive credential rotation exercise across all affected accounts and platforms.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.