CertiCon Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The CertiCon Listed by dragonforce Ransomware Group (reported July 25, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
When a company that builds technology for healthcare and telecommunications appears on a ransomware group's leak site, the immediate concern is practical rather than abstract. Employees, partners, and anyone whose details sit in internal systems may face the risk that private files have left the organisation's control. Public reporting on 25 July 2024 stated that CertiCon, a Czech firm, had been listed by the dragonforce ransomware group after an attack in which internal files were claimed to have been exfiltrated. The number of people affected remains unknown, and the precise contents of those files have not been detailed beyond the general description of internal material.
For ordinary people connected to the company—staff, contractors, or individuals whose data might appear in project or support records—the listing raises straightforward questions about exposure and next steps. What is known so far is limited to the group's claim and the organisation's sector; much else is still unconfirmed.
Breaking down the breach
According to public reporting dated 25 July 2024, CertiCon was listed by the dragonforce ransomware group. The available summary states that internal files were exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been released, and details such as the exact date of intrusion, the technical method used, the volume of data taken, or any ransom demand remain undisclosed. The listing itself constitutes a claim by the group rather than an independently verified confirmation of every asserted detail. At present, public information stops at the fact of the listing and the description of internal files as the material involved.
Who is dragonforce?
Dragonforce is a ransomware operation that has appeared in public reporting as a group conducting double-extortion attacks: encrypting systems while also stealing data and threatening to publish it if payment is not made. Like other groups in this category, it maintains a leak site on which it lists victims and, in some cases, releases samples or larger archives of purportedly stolen material. Public accounts of its activity describe the use of ransomware tools, pressure tactics against organisations, and the publication of claims about successful breaches. These patterns are drawn from widely reported prior incidents involving the group; they do not automatically prove every specific assertion made about any single victim. In the present case, dragonforce's listing of CertiCon should be treated as the group's claim that it obtained and intends to leverage internal files from the company.
About CertiCon
CertiCon is a Czech company focused on technological innovation and the development of software and hardware solutions, particularly for the healthcare and telecommunications sectors. Organisations of this type typically work with product designs, source code, project documentation, customer or partner information, and internal operational records. Because healthcare and telecom environments often involve regulated or sensitive systems, a breach at a technology supplier can carry consequences beyond the company itself—potentially affecting clients who rely on its products or services. The listing therefore matters not only for CertiCon's own staff and operations but also for the wider ecosystem that depends on its work. No public statement from the company confirming or denying the full extent of the incident is included in the available facts.
The information in question
The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as employee records, customer lists, source code, medical-related data, financial documents, or authentication credentials—has been publicly detailed. Exact contents therefore remain unconfirmed. Companies engaged in healthcare and telecommunications technology commonly hold design files, development repositories, correspondence, contracts, and personnel or partner data. Whether any of those categories were among the files claimed by dragonforce is not established in the public record. Readers should treat any more specific descriptions that appear later as requiring independent verification.
Why it matters
For individuals, the practical risk is that personal or professional information contained in internal files could be misused for phishing, identity fraud, or targeted social engineering. Even if the files are primarily technical, they may still contain names, email addresses, project roles, or contact details that make subsequent scams more convincing. For the organisation, the consequences include potential operational disruption, regulatory scrutiny in sectors that handle sensitive systems, loss of trust among clients, and the cost of investigation and remediation. Because the scale of the incident and the precise data types remain unknown, the full impact cannot yet be quantified. The listing alone, however, is sufficient to warrant caution among anyone who has had a working relationship with CertiCon.
If your data was in this claimed breach
If you believe your information may have been held by CertiCon—whether as an employee, contractor, partner, or client—begin with basic protective steps. Change passwords on any accounts that used the same credentials or email address associated with the company, and enable multi-factor authentication wherever it is available. Monitor financial and email accounts for unexpected activity, and treat unsolicited messages that reference the company or its projects with extra scepticism. Keep records of any suspicious contact. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a check does not confirm involvement in this specific incident but can indicate whether the address has surfaced elsewhere. Further official guidance may emerge if CertiCon or relevant authorities release additional Reported Details.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
PER4MANCE Listed by dragonforce Ransomware GroupCogitis Listed by dragonforce Ransomware GroupMobigator Technology Group Listed by dragonforce Ransomware GroupGeologics Listed by dragonforce Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the CertiCon Listed by dragonforce Ransomware Group →
Publicly posted by dragonforce — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.