Division 10 Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Division 10 was listed by the dragonforce ransomware group on November 30, 2025, after internal files were exfiltrated in an attack whose timing has not been established. Individuals should review any notifications from the organisation and take steps to protect their information.
Division 10, a Memphis-based supplier of specialty construction products, was listed by the ransomware group dragonforce on November 30, 2025. The listing states that internal files were exfiltrated during a ransomware attack, though the number of individuals affected and the precise contents of those files remain undisclosed.
The incident matters because Division 10 has operated since 1989 in a sector that routinely exchanges project details, pricing, and contact information with contractors and other businesses. Any exposure of such records could affect parties who have interacted with the company over decades.
Inside the incident
The only confirmed public detail is the November 30, 2025 listing itself. No information has been released on when the intrusion began, how long the attackers had access, or the volume of data involved. The reported summary describes the event as a ransomware attack in which internal files were removed, but provides no further technical description or confirmation of encryption or other actions.
Who is dragonforce?
Dragonforce is a ransomware group that has appeared on leak sites in connection with multiple incidents. Like other actors in this category, it typically claims to have obtained data from targeted organizations and uses public listings to pressure victims. Such groups commonly rely on initial access obtained through phishing, compromised credentials, or unpatched systems, followed by data exfiltration before deploying encryption. Their listings represent claims made by the group rather than independently verified events unless corroborated by the affected organization or law enforcement.
Who is Division 10?
Division 10 Inc. is a Tennessee company that has supplied specialty products to the construction industry since 1989. Its services include product sales, estimating, and installation quotes, serving contractors as well as clients in sectors such as automotive manufacturing. Organizations of this type maintain records related to bids, project specifications, supplier agreements, and customer contacts as part of routine operations.
What data was at risk
The listing refers only to “internal files exfiltrated.” No inventory of specific data types has been published. Companies in the construction supply sector commonly hold project documentation, pricing information, contractor details, and basic business correspondence. Whether any of these categories were among the files removed in this case has not been confirmed.
What's at stake
For individuals or firms whose information appears in Division 10 records, the primary concerns are potential misuse of contact details or project data for further targeting, and the possibility that business-sensitive information could be used by competitors or other parties. For the company itself, the incident adds the costs of investigation, possible remediation, and any resulting loss of client trust. Because the scale of exposure is unknown, the full extent of these effects cannot yet be assessed.
If your data was in this claimed breach
Monitor accounts and email addresses associated with any past dealings with Division 10 for unusual activity. Review and update passwords for any shared portals or vendor systems, and enable multi-factor authentication where available. Individuals can also run a free exposure scan of their email address against known breach data to determine whether their information has appeared in previously published datasets. Organizations should contact Division 10 directly for any official notification or guidance they may issue.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
A.S.A.P. Restoration Listed by dragonforce Ransomware GroupKing City Lumber Listed by dragonforce Ransomware GroupShelbra International Listed by dragonforce Ransomware GroupSummit Construction Supply Listed by dragonforce Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Division 10 Listed by dragonforce Ransomware Group →
Publicly posted by dragonforce — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.