Jan Nygaard Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Jan Nygaard was listed by the dragonforce ransomware group on January 25, 2025, after internal files were exfiltrated in a ransomware attack. Individuals are advised to check whether their information was affected and to take appropriate protective measures.
When a company is named on a ransomware group's leak site, the immediate concern for employees, partners and anyone whose details sit in its systems is simple: what information may now be outside the organisation's control, and what can be done about it. Public reporting on 25 January 2025 listed Jan Nygaard, a Danish industrial-machinery firm, among the claims made by the group known as dragonforce. The number of people affected remains unknown, and the precise contents of any taken data have not been independently confirmed.
What is known is limited to the listing itself and a short description of the company. For those who deal with Jan Nygaard, the practical stakes are the usual ones that follow any claimed ransomware incident involving internal files: possible exposure of business records, contact details or other material that could be misused for fraud or further targeting. Until more detail emerges, caution and basic protective steps remain the most useful response.
Inside the incident
According to the available record, Jan Nygaard was listed by the dragonforce ransomware group on or around 25 January 2025. The report states that internal files were exfiltrated in a ransomware attack. No further technical detail—such as the initial access method, the exact date of intrusion, the volume of data taken, or whether systems were encrypted—has been disclosed in the public summary. The number of individuals whose information may be involved is listed as unknown.
Ransomware incidents of this type typically involve both encryption of systems and the theft of data for leverage. In this case the public description focuses on the claim of exfiltration of internal files. Because the listing originates from the threat actor's own channel, it should be treated as an unverified claim rather than confirmed fact until the organisation or independent investigators provide additional verification. No dollar figures, file counts or specific system names appear in the reported material.
Who is dragonforce?
Dragonforce is a ransomware group that has operated in recent years by combining encryption of victim systems with the threat of data publication. Like many contemporary ransomware operations, it maintains a leak site on which it names organisations it claims to have compromised and, in some cases, posts samples or larger volumes of stolen material. The group has been observed using double-extortion tactics: demanding payment both to restore access and to prevent public release of data.
Public reporting on dragonforce describes it as following patterns common to ransomware-as-a-service style activity—affiliates or operators gain access, deploy ransomware, and use the leak site for pressure. Prior listings have involved companies across multiple sectors and countries. In the present matter the group claims to have listed Jan Nygaard; no independent confirmation of the technical details of that claim is contained in the facts available here. Readers should therefore regard the listing as an assertion by the actor rather than established fact.
About Jan Nygaard
Jan Nygaard is described as a company operating in the industrial machinery and equipment sector. It is headquartered in Glostrup, in Denmark's Capital Region, employs between 100 and 249 people, and reports annual revenue in the range of 10 million to 25 million (currency not further specified in the summary). Firms of this type typically design, manufacture, supply or service machinery used in manufacturing, construction or related industrial processes.
Organisations in this sector routinely hold commercial contracts, supplier and customer records, technical documentation, employee information and operational data. A claimed breach is consequential because such material can reveal business relationships, pricing, technical know-how or personal contact details. Even without confirmation of the full scope, the mere listing raises questions for partners and staff about whether their information was among any files taken. The company has not been publicly characterised in the available record as having confirmed or denied the claim.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory—such as specific categories of personal data, financial records, or technical drawings—has been named. For an industrial-machinery company of this size, internal files commonly include correspondence, project documentation, employee and contractor records, customer and supplier lists, and operational or financial documents. Whether any of those categories were present in the material claimed by dragonforce remains unconfirmed.
Because the exact contents are not disclosed, it is not possible to state with certainty what types of personal or commercial data may have left the organisation. The public record simply records the claim of internal-file exfiltration. Affected individuals and counterparties should therefore assume that ordinary business and contact information could be involved until clearer information is released by the company or by investigators.
What's at stake
For people whose details may appear in the files, the concrete risks are familiar: phishing or social-engineering attempts that reference real business relationships, attempts to reset accounts using known email addresses, or the reuse of any exposed credentials on other services. Business partners may face targeted fraud that impersonates Jan Nygaard staff or references genuine contracts. The organisation itself faces potential operational disruption, reputational questions, and the cost of investigation and remediation—none of which have been quantified in the public summary.
Because the number of people affected is unknown and the data types remain broadly described, the scale of any harm cannot yet be measured. The absence of confirmed detail does not eliminate risk; it simply means that precautionary measures are the prudent course for anyone who has had dealings with the company.
What to do if you're exposed
If you have worked with, supplied, or been employed by Jan Nygaard, treat any unexpected messages that reference the company or its staff with extra scrutiny. Change passwords on accounts that used the same credentials as any work-related systems, enable multi-factor authentication where available, and monitor financial and email accounts for unusual activity. Be alert to phishing that may use real names or project details. Organisations that hold data about you can also be asked what they know about the incident and what steps they are taking.
Readers can run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such checks do not prove or disprove involvement in this specific incident, but they provide a practical starting point for understanding whether personal information is circulating more widely. Stay informed through official statements from the company rather than relying solely on claims posted by threat actors.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Yem Chio Co Listed by dragonforce Ransomware GroupBurnex Listed by dragonforce Ransomware GroupBMW Guatemala Listed by dragonforce Ransomware GroupBarnes & Jones Listed by dragonforce Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Jan Nygaard Listed by dragonforce Ransomware Group →
Publicly posted by dragonforce — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.