Quick Summary
AllegedExecutive Summary
Shillen Mackall & Seldon, a business services firm operating in the United States, was identified as a victim of the dragonforce ransomware group. The listing on the group’s dark web portal was published on July 15, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. The organization functions within the professional and legal services sector. This event places Shillen Mackall & Seldon among numerous other victims claimed by dragonforce, with several other business services companies in the US also listed on the same day. In the 60 days leading up to this listing, dragonforce claimed a significant number of victims, totaling 78, positioning it as one of the most prolific actors currently under observation. The group predominantly targets the business services, manufacturing, and technology sectors, with a strong concentration of victims located in the United States, the United Kingdom, and Germany. Shillen Mackall & Seldon’s profile aligns closely with the group’s typical victimology, particularly concerning other business services organizations that have been targeted, such as Hughes Atwood & Mullaly pllc, Heritage Mechanical LLC, Road Ahead Technologies Consultant, and Graphic International Centre.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry for the domain promotingjustice.com did not yield any relevant records within the queried dataset. It is crucial to understand that a negative result from this specific query does not definitively confirm that the organization is unaffected. The telemetry data represents a partial, paginated sample from a single source at a particular time. Potential exposures may be masked by alternate corporate domains, the use of personal email aliases for work-related accounts, or data that was harvested and subsequently rotated before being indexed in the queried feeds. The absence of evidence in this specific query does not preclude the possibility of a compromise, especially since the domain appeared in a batch digest of other dragonforce listings from the same date. Ransomware groups like dragonforce frequently leverage credentials obtained from infostealers as a primary method for initial access. Threat actors or initial access brokers typically acquire these credentials from underground marketplaces, validate them to gain entry into corporate environments through platforms such as Microsoft 365, VPNs, or remote-access portals, and subsequently deploy ransomware. The current query’s lack of evidence does not eliminate this potential intrusion vector, as credentials could exist in other data feeds, may have been rotated prior to indexing, or could have been harvested using personal email aliases associated with the corporate domain. Consequently, CTI teams should maintain vigilance and continue monitoring for any emerging threat intelligence. Proactive measures such as credential hygiene checks, password rotation, and multi-factor authentication reviews remain essential. Monitoring alternate corporate domains and reviewing activity logs for Microsoft 365, VPNs, and remote-access systems are recommended steps to further bolster the organization’s security posture against potential threats.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.