North Central HIDTA
Attack Intelligence
North Central HIDTA was compromised in a ransomware attack attributed to dragonforce in March 2026. The organization, operating in an undisclosed sector in United States, was added to the group's data leak site as part of an extortion campaign.
dragonforce operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
North Central HIDTA is a federal program aimed at uniting federal, state, local, and tribal law enforcement agencies to combat drug trafficking activities in Minnesota and Wisconsin. By creating multi-agency task forces, the initiative works to reduce significant drug threats and enhance community safety. The organization focuses on intelligence sharing and coordinated law enforcement strategies to disrupt drug trafficking organizations and related violence. Additionally, North Central HIDTA provides targeted training for public safety and health professionals to further support drug enforcement and treatment efforts.
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2025-5777, which may have been leveraged as initial access vectors or for lateral movement.