Vermont XCenter Data Breach

Alleged

Ransomware claim involving Vermont XCenter

Published: Aug 17, 2026 DragonForce
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Vermont XCenter
Industry
Business Services
Threat Actor
DragonForce
Date of Incident
Aug 17, 2026

Executive Summary

DragonForce ransomware claimed Vermont XCenter as a victim on August 17, 2026, as identified by SOCRadar’s Dark Web Monitoring service. Vermont XCenter operates in Brazil, providing business services and solutions through its domain vermont[.]com[.]br. This claim aligns with a significant 20-month period of exposed stealer-log data, encompassing credentials for both Microsoft 365 and the GoTo collaboration platform. Such a broad exposure of credentials for critical communication and collaboration tools could grant attackers extensive organizational access with relatively low effort. In the 60 days preceding this listing, DragonForce claimed 41 other victims. Their primary targeting has been in the Business Services and Manufacturing sectors, with a significant geographic focus on the United States, the United Kingdom, and China. While Vermont XCenter is not within this primary cluster, DragonForce has recently shown interest in the Latin American region, with prior victims including Ifage, DEGEREMCIA, and GB Group S.A. This indicates a continued focus on expanding their operational reach into regions outside their traditional core.

Technical Analysis

SOCRadar telemetry identified 26 records associated with the domain vermont[.]com[.]br. Of these, two records are classified as employee-on-org-systems, specifically a @vermont.com.br user account detected on Microsoft 365 (login.microsoftonline[.]com) and the same user appearing twice on the GoTo collaboration platform (identity.goto[.]com). An additional eleven records show external or consumer-email usernames associated with target-owned portals, including servlink.vermont[.]com[.]br and mutant.vermont[.]com[.]br. Furthermore, three @vermont.com.br corporate credentials were found on third-party services, such as Zendesk. The identified stealer-log records have dates spanning from December 2024 up to August 12, 2026, indicating a credential exposure window of approximately 20 months without any apparent rotation. The combination of access to a Microsoft 365 tenant and the GoTo identity platform presents a substantial surface for lateral movement within an organization’s communications and remote access infrastructure. This pattern suggests a broad-based credential compromise, potentially sourced from initial access brokers, rather than a highly targeted, specific intrusion campaign. This extensive exposure of credentials, particularly for critical systems like Microsoft 365 and GoTo, without evidence of rotation over a significant period, necessitates immediate attention. Organizations should prioritize comprehensive credential hygiene. This includes enforcing mandatory password resets for all affected @vermont.com.br accounts found on identity.goto[.]com and login.microsoftonline[.]com. A thorough audit of the Microsoft 365 tenant and GoTo activity logs from July 2026 onward is recommended to identify any anomalous session activity.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.