The DragonForce ransomware group has claimed responsibility for a devastating cyberattack against the Belk department store chain in the United States.
See also: Interlock ransomware group uses new RAT malware

The incident was discovered on May 8 and led Belk to take down affected systems, restrict access , reset passwords and rebuild affected systems — actions that disrupted physical and online stores for several days. The online store remains down.
Belk's investigation into the attack revealed that hackers accessed its network from May 7 to 11, during which time they extracted a number of documents, including files containing personal information.
In a notification filed with the New Hampshire Attorney General's Office, Belk said at least names and Social Security numbers were leaked due to the attack.
See also: Russian basketball player arrested for involvement in ransomware attacks
The company is offering affected individuals 12 months of free credit monitoring and identity restoration services, which also include up to $1 million. The company has not named the group behind the attack, but the DragonForce ransomware gang claimed responsibility on Monday, adding Belk to leak site on the Tor network.

DragonForce claims to have extracted 156 gigabytes of data from the department store chain and has made it available for download, suggesting that Belk did not pay a ransom.
DragonForce has been active since at least December 2023 and operates as ransomware-as-a-service (RaaS), having allegedly targeted around 210 organizations — although only 38 incidents have been confirmed to date.
The hacking group has recently been in the news after a series of devastating attacks on UK retail chains including Co-op, Harrods and Marks & Spencer. These attacks have been linked to the notorious cybercriminal organisation known as Scattered Spider.
See also: BERT Ransomware disables ESXi virtual machines
Based on the above, there is a growing trend of targeted attacks on major retail chains in both the US and the UK, aimed at stealing personal data and pressuring for ransom payments. These attacks not only cause financial loss and operational disruption, but also a serious blow to customer trust.
Source: securityweek
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
