Conrad Capital Management Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Conrad Capital Management was listed by the dragonforce ransomware group on March 18, 2026, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone who has a relationship with the firm should verify whether their data was involved and take appropriate protective steps.
Conrad Capital Management, a registered investment advisory firm, was listed on March 18, 2026, by the ransomware group dragonforce. The listing states that internal files were exfiltrated during a ransomware attack and that the data include customer personal information and financial records. The number of individuals affected remains unknown, and no further details on the scale or method of the intrusion have been publicly confirmed.
Such listings have become a routine feature of the current ransomware landscape, where groups combine file encryption with the threat of data release to pressure victims. For a firm that holds client financial and personal records, even an unverified claim of exposure raises immediate questions about data handling and client notification obligations.
Inside the incident
The only confirmed public information is the March 18, 2026 listing itself. The entry asserts that internal files containing customer personal information and financial data were taken. No independent confirmation of the volume of data, the encryption status of systems, or any ransom demand has been released. The number of people whose information may be involved is not stated.
Who is dragonforce?
Dragonforce is a ransomware operation that maintains a leak site to publish names of organizations it claims to have targeted. Like other groups in this category, it typically uses a double-extortion model: encrypting files on compromised systems and threatening to publish stolen data if a ransom is not paid. The group has appeared in multiple public reports over recent years, though specific tactics and infrastructure change frequently as law-enforcement actions and security improvements force adaptation.
The listing of Conrad Capital Management constitutes the group’s claim of responsibility. No additional statements or evidence from dragonforce about this particular case have been independently verified.
About Conrad Capital Management
Conrad Capital Management is an independent registered investment advisory firm founded in 1998. It provides personalized financial advice and investment counseling to individual and institutional clients across the United States, with services that include fixed-income portfolio management, alternative investments, retirement planning, and customized portfolio strategies. As a fiduciary, the firm is obligated to act in clients’ best interests when managing or advising on financial assets.
Organizations of this type routinely process sensitive client data, including account numbers, tax identifiers, investment holdings, and contact details. A breach affecting such records therefore touches both regulatory compliance requirements and the privacy expectations of long-term clients.
What was likely exposed
The listing names internal files that contain customer personal information and financial data. No inventory of specific file types, record counts, or date ranges has been published. While firms in this sector commonly store client statements, KYC documentation, account credentials, and transaction histories, the precise contents of the exfiltrated material remain unconfirmed beyond the general description provided in the claim.
Why it matters
Personal and financial data held by investment advisers can be used for identity theft, account takeover attempts, or targeted fraud. Clients may face the need to monitor credit reports, change account access credentials, or respond to unsolicited contact that exploits the exposed information. For the firm, the incident adds to the operational burden of incident response, potential regulatory inquiries, and the task of restoring client confidence.
Because the number of affected individuals is unknown, the full scope of downstream risk cannot yet be measured.
Were you affected?
Individuals who are clients of Conrad Capital Management should contact the firm directly for information on any notification process. Practical steps include reviewing recent account statements for unauthorized activity, enabling multi-factor authentication on all financial accounts, and placing fraud alerts with credit bureaus if statements or tax documents appear to have been exposed. Readers can also run a free exposure scan of their email address against known breach data sets to check for prior appearances of their information in public leaks.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Delbrook Capital Advisors Listed by dragonforce Ransomware Groupepbinsurance.com Listed by dragonforce Ransomware GroupFirst Trinity Financial Listed by dragonforce Ransomware GroupOriska Insurance Listed by dragonforce Ransomware GroupLatest breaches
Publicly posted by dragonforce — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.