RANSOMWARE VICTIMFINANCIAL SERVICES

One Community FCU

dragonforce📍 United States (US)📅 July 21, 2026
1
linked CVEs
8
same group

Attack Intelligence

One Community FCU was compromised in a ransomware attack attributed to dragonforce in July 2026. The organization, operating in the Financial Services sector in United States, was added to the group's data leak site as part of an extortion campaign.

dragonforce operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

One Community FCU offers a range of financial services including loans, savings accounts, and online banking solutions. Their products cater to individuals seeking personal, auto, mortgage, and credit card loans, as well as those interested in savings and checking accounts. In this release we provide a portion of the documentation we obtained from the company: databases, internal documentation, client data, client documents, client financial information (including statements that clients supplied to One Community FCU from other banks), documentation on delinquent payments. Additionally, the release contains reports and documentation produced by TraceSecurity LLC (6300 Corporate Blvd, Suite 200, Baton Rouge, LA 70809). TraceSecurity LLC handled security matters for One Community FCU. In our view, that work was performed very poorly. These shortcomings contributed to the data breach, though they were not the sole cause, so we believe it is necessary to publish them.

Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2025-5777, which may have been leveraged as initial access vectors or for lateral movement.

Additional Details

Correlated Vulnerabilities (1)

Other Victims — dragonforce (8)

Quick Facts

CountryUnited States (US)
SectorFinancial Services
Attack DateJul 21, 2026
Intel Sourceransomware.live

Threat Group

dragonforce
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.