Fountain
Attack Intelligence
Fountain was compromised in a ransomware attack attributed to dragonforce in April 2026. The organization, operating in an undisclosed sector in Unknown, was added to the group's data leak site as part of an extortion campaign.
dragonforce operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Over the last 40 years, Fountain has established itself as Europe's leading supplier of drinks vending machines for businesses, delivering the widest range of solutions to organisations with 5 to 50 employees, as well as multi-site key account customers. The company now operates in 28 countries and has developed a strong reputation and identity, founded on personalised services and solutions, a wide range of tailor-made products, and a local distribution network. Here at Fountain, we provide our customers with a comprehensive service that covers cartridge and automatic machines, capsule machines, water fountains, accessories and snacks. Fountain distributes a vast range of both own-brand and third-party products. As such, it is able to meet the exacting demands of businesses and organisations looking to tailor their offer to the specific needs of their customers and/or staff, from precise quantities to consumer preferences. Fountain has been listed on the Euronext stock exchange since
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2025-5777, which may have been leveraged as initial access vectors or for lateral movement.