LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Conrad Capital Management Listed by dragonforce Ransomware Group

HIGH severityUnverified claimHow we verify

Conrad Capital Management Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 18, 2026
Conrad Capital Management Listed by dragonforce Ransomware Group

Reported March 18, 2026.

HIGH
Severity
March 18, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Conrad Capital Management was listed by the dragonforce ransomware group on March 18, 2026, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone who has a relationship with the firm should verify whether their data was involved and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Conrad Capital Management, a registered investment advisory firm, was listed on March 18, 2026, by the ransomware group dragonforce. The listing states that internal files were exfiltrated during a ransomware attack and that the data include customer personal information and financial records. The number of individuals affected remains unknown, and no further details on the scale or method of the intrusion have been publicly confirmed.

Such listings have become a routine feature of the current ransomware landscape, where groups combine file encryption with the threat of data release to pressure victims. For a firm that holds client financial and personal records, even an unverified claim of exposure raises immediate questions about data handling and client notification obligations.

Inside the incident

The only confirmed public information is the March 18, 2026 listing itself. The entry asserts that internal files containing customer personal information and financial data were taken. No independent confirmation of the volume of data, the encryption status of systems, or any ransom demand has been released. The number of people whose information may be involved is not stated.

Who is dragonforce?

Dragonforce is a ransomware operation that maintains a leak site to publish names of organizations it claims to have targeted. Like other groups in this category, it typically uses a double-extortion model: encrypting files on compromised systems and threatening to publish stolen data if a ransom is not paid. The group has appeared in multiple public reports over recent years, though specific tactics and infrastructure change frequently as law-enforcement actions and security improvements force adaptation.

The listing of Conrad Capital Management constitutes the group’s claim of responsibility. No additional statements or evidence from dragonforce about this particular case have been independently verified.

About Conrad Capital Management

Conrad Capital Management is an independent registered investment advisory firm founded in 1998. It provides personalized financial advice and investment counseling to individual and institutional clients across the United States, with services that include fixed-income portfolio management, alternative investments, retirement planning, and customized portfolio strategies. As a fiduciary, the firm is obligated to act in clients’ best interests when managing or advising on financial assets.

Organizations of this type routinely process sensitive client data, including account numbers, tax identifiers, investment holdings, and contact details. A breach affecting such records therefore touches both regulatory compliance requirements and the privacy expectations of long-term clients.

What was likely exposed

The listing names internal files that contain customer personal information and financial data. No inventory of specific file types, record counts, or date ranges has been published. While firms in this sector commonly store client statements, KYC documentation, account credentials, and transaction histories, the precise contents of the exfiltrated material remain unconfirmed beyond the general description provided in the claim.

Why it matters

Personal and financial data held by investment advisers can be used for identity theft, account takeover attempts, or targeted fraud. Clients may face the need to monitor credit reports, change account access credentials, or respond to unsolicited contact that exploits the exposed information. For the firm, the incident adds to the operational burden of incident response, potential regulatory inquiries, and the task of restoring client confidence.

Because the number of affected individuals is unknown, the full scope of downstream risk cannot yet be measured.

Were you affected?

Individuals who are clients of Conrad Capital Management should contact the firm directly for information on any notification process. Practical steps include reviewing recent account statements for unauthorized activity, enabling multi-factor authentication on all financial accounts, and placing fraud alerts with credit bureaus if statements or tax documents appear to have been exposed. Readers can also run a free exposure scan of their email address against known breach data sets to check for prior appearances of their information in public leaks.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyConrad Capital Management security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Conrad Capital Management’s full breach history →

More recent breaches

Delbrook Capital Advisors Listed by dragonforce Ransomware GroupMay 27, 2026epbinsurance.com Listed by dragonforce Ransomware GroupMay 25, 2026First Trinity Financial Listed by dragonforce Ransomware GroupApril 1, 2026Oriska Insurance Listed by dragonforce Ransomware GroupMarch 20, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Conrad Capital Management Listed by dragonforce Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by dragonforce — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram