Quick Summary
AllegedExecutive Summary
The DragonForce ransomware group has listed Graphic International Centre, a business services company based in the UAE, on its dark web leak portal. The listing occurred on July 14, 2026, and was identified by SOCRadar’s Dark Web Monitoring service. This incident highlights DragonForce’s continued targeting of the business services sector, which is their leading vertical, and expands their geographical reach into the Middle East.
Technical Analysis
Analysis of SOCRadar’s stealer-log telemetry revealed significant credential exposure for the graphicint[.]com domain. This included corporate credentials for the organization’s internal Outlook Web Access server (outlook.graphicint[.]com/owa), indicating a direct compromise of internal email infrastructure. The same logs contained corporate @graphicint[.]com usernames linked to various third-party services, including UAE government portals, a supplier portal, and a Ricoh platform. The widespread use of stolen credentials from a single compromised employee across both internal and external services suggests a potential initial access vector for the ransomware group. The exposure window for these credentials spans from September 2025 to mid-July 2026. DragonForce and similar groups commonly leverage these harvested credentials for initial access, often logging into systems like Microsoft 365, VPNs, or remote access portals before deploying ransomware. While the stealer-log evidence does not definitively confirm the use of these specific credentials by DragonForce, the direct exposure of internal OWA logins aligns with the typical kill chain observed in such incidents.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.