Amla Commerce
Attack Intelligence
Amla Commerce was compromised in a ransomware attack attributed to dragonforce in December 2025. The organization, operating in the Technology sector in United States, was added to the group's data leak site as part of an extortion campaign.
dragonforce operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Amla Commerce develops ecommerce software platforms. Architected with a focus on long-term sustainability, the platforms offer unmatched flexibility and scalability, as well as premium feature sets and deep functionality proven to enable growth and support even the most complex operational needs for mid-market and enterprise-level companies. Amla Commerce is the parent company of Artifi Labs, an enterprise product customization platform, and Znode, a .NET ecommerce platform with headless architecture and multi-store capabilities. Artifi and Znode power the ecommerce experiences of hundreds of companies across dozens of industries including apparel and soft goods, promotional products, uniforms, CPG and retail. Amla Commerce is a privately-held company, headquartered in Milwaukee, WI.
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2025-5777, which may have been leveraged as initial access vectors or for lateral movement.