Atcom Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Atcom has been listed by the dragonforce ransomware group, with internal files reported as exfiltrated in an attack disclosed on July 14, 2026. An undisclosed number of people may have been affected; check your account status and change passwords if you have any connection to Atcom.
Inside the incident
The only confirmed information is the listing itself and the claim that files were removed from Atcom systems. No date of the intrusion, method of entry, or confirmation that any data was later published has been released. The scale of the operation and whether any ransom demand was issued or met remain undisclosed.
Who is dragonforce?
Dragonforce is a ransomware group that has conducted operations against multiple organizations in recent years. Like other groups in this category, it typically deploys encryption on targeted networks and removes copies of files beforehand. When a payment is not received, the group lists the victim on a public leak site and may release portions of the material it claims to hold. Its listings are presented as claims by the group and are not independently verified at the time they appear.
Who is Atcom?
Atcom, operating as ATCOM Technology Co., LTD., manufactures VoIP hardware and software. Its product range includes IP phones, IP PBX systems, and solutions for self-hosted, cloud, call-center, and Wi-Fi voice services aimed at enterprise customers. Companies in this sector routinely process configuration data, call records, and customer account information as part of their normal operations.
What was likely exposed
The listing refers only to “internal files exfiltrated in ransomware attack.” No inventory of specific file types or data categories has been published. Organizations that supply business communication systems commonly hold customer contact details, network configurations, and service records, yet the precise contents allegedly taken from Atcom have not been confirmed.
Why it matters
Stolen internal files from a VoIP manufacturer could contain information about client networks and communication setups. If such material later appears online, affected businesses may face increased risk of targeted follow-on attacks or misuse of their configuration data. Individuals whose contact or account details sit inside those files would have limited visibility into how the information might be used.
If your data was in this claimed breach
Monitor accounts associated with any business communications services you use and watch for unusual login attempts. Enable multi-factor authentication where available and review recent activity on any VoIP or cloud telephony platforms. Readers can run a free exposure scan of their email address against known breach data to check whether their information has appeared in previously published sets.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Road Ahead Technologies Consultant Listed by dragonforce Ransomware GroupEdison Global Networks Limited Listed by dragonforce Ransomware GroupNewNet Listed by dragonforce Ransomware GroupOmax Autos Listed by dragonforce Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Atcom Listed by dragonforce Ransomware Group →
Publicly posted by dragonforce — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.