LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ikav Global Energy Listed by dragonforce Ransomware Group

HIGH severityUnverified claimHow we verify

Ikav Global Energy Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 28, 2024
Ikav Global Energy Listed by dragonforce Ransomware Group

Reported December 28, 2024.

HIGH
Severity
December 28, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Ikav Global Energy was listed by the dragonforce ransomware group on 28 December 2024 after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; anyone connected to the company should verify their exposure and take protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On December 28, 2024, the international asset management firm Ikav Global Energy was listed by the ransomware group dragonforce. Public reporting indicates that internal files were exfiltrated as part of a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed.

The listing places the organisation among those claimed as victims by the group. For institutional investors, employees, and partners who interact with energy-infrastructure asset managers, such an incident raises concrete questions about the exposure of internal business information and the potential for secondary misuse.

Inside the incident

According to available public information, Ikav Global Energy was named on a dragonforce-associated listing dated December 28, 2024. The reported summary states that internal files were exfiltrated in a ransomware attack. No confirmed figures have been released for the volume of data taken, the precise systems involved, or the timeline of initial access and encryption. The number of individuals whose information may have been included is listed as unknown. Method of intrusion, ransom demands, and any subsequent negotiation or recovery steps remain undisclosed in the public record.

Because the primary source of the claim is the group’s own listing, the assertion that Ikav Global Energy was successfully compromised should be treated as an unverified claim pending independent confirmation by the organisation or law-enforcement authorities. No additional technical indicators or forensic findings have been made public at the time of reporting.

The group behind it: dragonforce

Dragonforce is a ransomware operation that has appeared in public threat reporting as a group employing double-extortion tactics: encrypting systems while also claiming to exfiltrate data and threatening to publish it on a dedicated leak site if payment is not made. Like other contemporary ransomware actors, it typically advertises victims on dark-web forums or dedicated portals, often including sample files or screenshots to pressure the target. Public knowledge of the group’s activity centres on opportunistic targeting of organisations across multiple sectors rather than exclusive focus on energy or finance.

In this case, dragonforce claims to have listed Ikav Global Energy and to have obtained internal files. No further statements attributed specifically to the group about this victim—such as data-volume claims, ransom amounts, or publication deadlines—appear in the provided facts. Established patterns associated with the group include the use of ransomware payloads, data theft prior to encryption, and public shaming via leak sites; these are general characteristics of the actor and should not be read as Reported Details of the Ikav Global Energy incident.

Who is Ikav Global Energy?

Ikav Global Energy, also referred to as IKAV, is an international asset management group that supplies institutional investors with investment solutions across a range of infrastructure energy assets. These include solar, concentrated solar power, wind, energy efficiency, geothermal, thermal power plants, and upstream energy projects. Organisations of this type typically manage portfolios on behalf of pension funds, insurers, and other large capital providers, handling sensitive commercial, financial, and operational information related to energy infrastructure.

A breach involving an asset manager in the energy sector is consequential because such firms sit at the intersection of capital markets and critical infrastructure. They routinely hold proprietary investment models, counterparty details, project documentation, and correspondence that could be of interest to competitors, opportunistic criminals, or state-aligned actors seeking economic or strategic insight. Even when personal data volumes are limited, the commercial sensitivity of internal files can create lasting operational and reputational effects.

What data was at risk

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as employee records, investor lists, financial statements, or project contracts—has been publicly confirmed. Exact contents therefore remain unconfirmed.

Organisations of this kind typically maintain a mix of corporate documents, investment theses, due-diligence materials, legal agreements, and communications with limited partners and portfolio companies. Some of these materials may contain personal data of employees, directors, or external contacts, while others are purely commercial. Because the precise inventory has not been disclosed, it is not possible to state which categories were actually taken. Readers should treat any specific claims about data types beyond “internal files” as unverified unless corroborated by the organisation itself.

Why it matters

For individuals whose contact or employment information may have been present in internal systems, the principal risks are phishing, social-engineering attempts that reference the firm, and potential identity-related misuse if personal identifiers were included. For the organisation, the consequences include possible regulatory notification obligations, disruption of investor relations, and the need to rebuild confidence among limited partners who entrust capital to energy-infrastructure vehicles.

Even when the scale of personal-data exposure is unknown, the mere existence of an exfiltration claim can enable fraudsters to craft more convincing approaches to staff, investors, or counterparties. On the organisational side, the incident underscores the value of internal files that describe deal pipelines, valuation methodologies, and operational performance of energy assets—information that, if misused, could affect competitive positioning or market perceptions.

Were you affected?

If you are an employee, investor contact, or business partner of Ikav Global Energy, monitor communications for unexpected requests that reference the firm or its projects. Enable multi-factor authentication on email and financial accounts, and treat unsolicited messages that cite the incident with caution. Consider changing passwords associated with any accounts that may have been used in correspondence with the organisation.

Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Such a scan provides an independent signal of prior exposure and can help prioritise further protective steps. Official statements from Ikav Global Energy, if and when issued, remain the authoritative source for confirmation of impact and any recommended remediation.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyIkav Global Energy security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Ikav Global Energy’s full breach history →

More recent breaches

Controlled Power Listed by dragonforce Ransomware GroupSeptember 9, 2024Hoppecke Listed by dragonforce Ransomware GroupJune 8, 2024WindCom Listed by dragonforce Ransomware GroupMay 16, 2024Erwat Listed by dragonforce Ransomware GroupFebruary 29, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Ikav Global Energy Listed by dragonforce Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by dragonforce — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram