RANSOMWARE VICTIMDUPLICATE CLAIM

GB Mail

gb-mail.co.uk
dragonforce📍 United Kingdom (GB)📅 November 7, 2025
1
linked CVEs
8
same group

Attack Intelligence

GB Mail was compromised in a ransomware attack attributed to dragonforce in November 2025. The organization, operating in an undisclosed sector in United Kingdom, was added to the group's data leak site as part of an extortion campaign.

dragonforce operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

GB Mail is a privately owned and leading mailing house located centrally in the home counties. With a strong ethos of delivering mail with no fuss, on time and in full, the company boasts a dedicated and knowledgeable team passionate about all aspects of print and mail. Their services include storage & fulfilment, postal solutions, print personalisation, database cleansing, international mail, direct mail, and subscription mail.

Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2025-5777, which may have been leveraged as initial access vectors or for lateral movement.

Additional Details

Correlated Vulnerabilities (1)

Other Victims — dragonforce (8)

Quick Facts

CountryUnited Kingdom (GB)
Attack DateNov 7, 2025
Domaingb-mail.co.uk
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

dragonforce
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.