Aptora
Attack Intelligence
Aptora was compromised in a ransomware attack attributed to dragonforce in June 2026. The organization, operating in the Technology sector in United States, was added to the group's data leak site as part of an extortion campaign.
dragonforce operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Aptora is an aggressively growing software company in Lenexa, KS. The company offers award-winning software and consulting services to the service and contracting industries. In 2006, the company were voted one of the top twenty-five companies in the Kansas City area by the Business Journal. Aptora also provides data hosting and processing services for its clients on its own infrastructure. During our visit, we took not only the company’s own data but also the databases of its clients. Unfortunately, the company showed no interest in preserving its clients’ data. When we contacted them, they told us the company had assured them there was no leak. That’s not true. For the release, we have prepared not only Aptora data but also archives containing the databases of more than 100 of its clients. This could affect Aptora leadership, and they may decide to prevent publication.
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2025-5777, which may have been leveraged as initial access vectors or for lateral movement.