LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › 5àSec Listed by dragonforce Ransomware Group

HIGH severityUnverified claimHow we verify

5àSec Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 2, 2025
5àSec Listed by dragonforce Ransomware Group

Reported July 2, 2025.

HIGH
Severity
July 2, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On 02 July 2025 it was publicly disclosed that the dry-cleaning chain 5àSec had been listed by the dragonforce ransomware group, which claimed to have exfiltrated internal files. Anyone connected to the organisation is advised to review any communications from 5àSec and to monitor their accounts for unusual activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 2 July 2025 the French dry-cleaning network 5àSec appeared on the leak site operated by the ransomware group dragonforce. Public reporting states that internal files were exfiltrated during a ransomware attack; the number of people affected remains unknown. The listing itself is a claim by the group and has not been independently confirmed in the available record.

Because 5àSec operates a large franchise network serving ordinary customers across several countries, any release of internal databases could expose personal and commercial information. The precise scale and contents of the material remain limited in public detail.

Inside the incident

According to the dragonforce listing dated 2 July 2025, the group asserts that it carried out a ransomware attack against 5àSec and exfiltrated internal files, including database dumps covering several countries in which the network is present. The group further claims that company representatives and investors dismissed the potential impact of publication, stating that customers were “not important” for a network of more than 2 000 dry cleaners. On that basis dragonforce says it decided to publish the data in full.

No independent confirmation of the intrusion method, the exact date of compromise, the volume of data taken, or the technical indicators of compromise has been released in the public record. The number of individuals whose information may be involved is listed as unknown. The only concrete description available is the group’s own statement that internal files and multi-country database dumps were obtained.

The group behind it: dragonforce

Dragonforce is a ransomware operation that follows the now-common double-extortion model: encrypting systems while simultaneously stealing data and threatening to publish it on a dedicated leak site if a ransom is not paid. Like other groups of this type, it typically advertises victims on a dark-web portal, posts samples or full archives, and pressures both the organisation and its partners or customers. Public reporting over recent years has linked dragonforce to attacks across multiple sectors and geographies, though the group’s precise internal structure and affiliate arrangements remain only partially documented.

In the present case the group’s leak-site entry constitutes an unverified claim. Nothing in the available facts establishes that dragonforce successfully encrypted 5àSec systems, that a ransom demand was made or refused, or that the posted material is authentic and complete. The statements attributed to 5àSec representatives and investors appear solely in the group’s own narrative.

Who is 5àSec?

5àSec is a long-established dry-cleaning and laundry franchise network founded in 1968. It grew from a concept of offering quality services at accessible prices and now operates more than 2 000 outlets across multiple countries, primarily in Europe and other regions. Franchisees handle everyday customer garments, corporate contracts and related logistics.

Organisations of this kind routinely maintain customer contact details, loyalty or account records, payment information, franchisee commercial data, employee records and operational databases spanning several national jurisdictions. A breach affecting such a network therefore has potential reach beyond a single corporate headquarters, touching both individual consumers who drop off clothing and the independent business owners who run local shops.

The information in question

The facts state only that “internal files” were exfiltrated and that the group claims to hold “database dumps for several countries of presence.” No further inventory—file names, record counts, data fields or sample contents—has been published in the public record. Exact contents therefore remain unconfirmed.

In the ordinary course of business a multi-country dry-cleaning franchise would be expected to hold customer names, addresses, telephone numbers, email addresses, order histories, payment-card tokens or invoices, franchisee financial and contractual data, and internal staff records. Whether any or all of these categories are present in the material dragonforce claims to possess cannot be verified from the information currently available.

What's at stake

If the claimed databases are authentic and are released, customers could face risks of phishing, identity fraud or unwanted contact based on their real names and contact details. Franchisees and commercial partners might see contractual or financial information exposed, creating competitive or legal complications. For 5àSec itself the incident raises questions of operational continuity, regulatory notification duties under data-protection laws in the countries of presence, and potential loss of trust among both consumers and investors.

Because the number of affected individuals is unknown and the precise data types unconfirmed, the concrete harm cannot yet be quantified. The principal immediate risk is the uncontrolled circulation of whatever material the group ultimately publishes.

Were you affected?

If you are a customer, franchisee or partner of 5àSec, monitor bank and card statements for unusual activity and treat unsolicited messages that reference dry-cleaning accounts or personal details with caution. Change passwords on any accounts that reuse credentials linked to 5àSec services, and enable multi-factor authentication where available. Consider placing fraud alerts with credit-reference agencies if you believe sensitive identifiers may have been involved.

Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Public detail on this incident remains limited; further verified information from 5àSec or independent investigators should be watched for as it becomes available.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Company5àSec security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See 5àSec’s full breach history →

More recent breaches

Persians - Cortinas - Todos - Alfombrass Listed by dragonforce Ransomware GroupNovember 13, 2025Groupe Courtois Automobiles Listed by dragonforce Ransomware GroupMarch 27, 2026Audexia group Listed by dragonforce Ransomware GroupFebruary 27, 2026MAIRIE DE FUMEL Listed by dragonforce Ransomware GroupFebruary 13, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the 5àSec Listed by dragonforce Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by dragonforce — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram