DragonForce and TheGentlemen Post New Victims on Leak Sites June 12 — Multi-Sector Global Blitz Continues as DragonForce Shows -95% MoM Activity Variance
Ransomware.live and BreachSense tracking shows fresh June 12 postings from DragonForce (Areco Steel/Sweden, Astec Valves/India, Hong Kong Parkview, Brian Cox Real Estate/UK) and TheGentlemen (Highwoods Properties, a U.S.-based commercial REIT), continuing their prolific double-extortion campaigns. DragonForce's leak site signals a sharp -95% month-over-month victim count reduction compared to its post-M&S/Co-op/Harrods peak, suggesting possible operational restructuring or affiliate churn, while TheGentlemen maintains steady cadence as the #2 most active RaaS group globally by cumulative 2026 victim count. Defenders in commercial real estate, manufacturing, and critical infrastructure should treat both groups as active, opportunistic threats with established affiliate pipelines.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the high severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.