Ifage Data Breach

Alleged

Ransomware claim involving Ifage.

Published: Jul 14, 2026 DragonForce
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Ifage
Industry
Business Services
Threat Actor
DragonForce
Date of Incident
Jul 14, 2026

Executive Summary

DragonForce ransomware has listed Ifage, an organization based in Switzerland, as a victim on its dark web leak portal on July 14, 2026. This incident was detected by SOCRadar’s Dark Web Monitoring service. While Ifage’s specific sector is not recorded, its inclusion brings another Swiss entity into DragonForce’s victim base. The ransomware group has been highly active in the 60 days prior to this listing, claiming 76 other victims and primarily targeting organizations in the business services, manufacturing, and technology sectors, with a strong presence in the United States, United Kingdom, and Germany.

Technical Analysis

Correlation of the DragonForce listing with SOCRadar’s stealer-log telemetry revealed a significant exposure related to the ifage[.]ch domain. The data indicates that employee credentials targeting internal systems, including the organization’s Exchange/OWA webmail (webmail.ifage[.]ch) and an HR portal (portailrh.ifage[.]ch), as well as numerous external-user accounts on a campus platform, were compromised. Evidence suggests at least one corporate username appeared across multiple internal endpoints and the HR portal, pointing to a compromised employee account and potential credential reuse. The exposure window spans from December 2024 to mid-July 2026, indicating that the compromised credentials were not rotated within this period, posing a high corporate intrusion risk. Infostealer-harvested credentials are a known entry vector for groups like DragonForce, who may purchase such logs to gain unauthorized access to systems through Microsoft 365, VPNs, or remote-access portals, ultimately leading to ransomware deployment. While the stealer-log evidence does not definitively confirm DragonForce’s direct use of these specific credentials, the compromised webmail and HR portal logins align with typical attack chains for this type of incident. Recommended actions include immediate password resets, enforcement of multi-factor authentication (MFA) on affected accounts, and endpoint forensics on the compromised user.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.