1. Executive summary
On 31 July 2026, the ransomware operator "dragonforce" publicly claimed a victim, Lamont Pridmore, a UK-based chartered accountancy practice operating across Northern England and Southern Scotland. The posted data consists of a single archive that expands to approximately 250 GB, reportedly containing both internal company documentation and client data with confidential financial information. Attribution to the "dragonforce" group is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data — and all technical detail in this advisory is single-sourced from the ransomware.live listing. EMEA financial services clients should treat this as a third-party supply-chain exposure event: a UK accountancy firm handling sensitive financial data for individuals and organisations has been publicly named with a large-volume data release.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The trigger facts available — a ransomware posting naming a UK accountancy firm — do not distinctively engage any article in the provided regulatory reference beyond what would be true of any security incident. If a client has a direct vendor or data-processing relationship with Lamont Pridmore, DORA Art. 28 (ICT third-party risk — general principles) and DORA Art. 30 (key contractual provisions with ICT third-party providers) may be engaged, but that depends on the client's specific contractual relationship with the victim, not on a fact present in this item.
3. Technical analysis & attack chain
No technical attack-chain detail is available in the source material. The ransomware.live listing provides only the following confirmed facts:
- Actor claim: The group "dragonforce" posted Lamont Pridmore as a victim on or before 31 July 2026.
- Victim profile: Lamont Pridmore is a chartered accountancy practice headquartered in Carlisle, serving Cumbria, Lancashire, and Southern Scotland. Service lines include asset and wealth management, corporate finance, tax planning, and general accountancy.
- Data volume: The posted leak consists of a single archive that expands to approximately 250 GB once unpacked.
- Data content: The archive reportedly contains internal company documentation and client data including confidential financial information.
- Victim domain: lamontpridmore.co.uk
Confidence caveat: All of the above is single-sourced from the ransomware.live platform, which indexes publicly visible posts by ransomware operators. No independent corroboration of the breach, the data volume, or the data contents has been identified. Attribution to "dragonforce" is unconfirmed — the actor has no MITRE ATT&CK profile in the verified reference data. No initial access vector, malware family, encryption behaviour, C2 infrastructure, persistence mechanism, or lateral movement detail is described in the available sources.
4. Mitigation & containment
P1 — within 24 hours
- Determine whether your organisation has a direct vendor, outsourcing, or data-processing relationship with Lamont Pridmore. If yes, initiate incident response under your third-party risk framework: contact the vendor's security or management contact, request a breach confirmation and scope statement, and identify what data of yours may be in the 250 GB archive.
- Search email and document repositories for any Lamont Pridmore correspondence, shared financial statements, tax filings, or client data that could indicate exposure scope.
- If Lamont Pridmore holds or processes your client data, begin a data-impact assessment to identify what categories of confidential financial information may be in the leaked archive.
P2 — within 72 hours
- If a third-party relationship is confirmed, document the exposure under your ICT third-party risk register and assess whether the incident meets your internal threshold for regulatory notification (e.g., personal data breach notification to the ICO under UK GDPR if personal data is involved — note: this is a data-protection obligation, not a DORA/NIS2 article, and is cited only as operational guidance).
- Review and where possible revoke any shared credentials, API keys, or access tokens previously exchanged with Lamont Pridmore systems or personnel.
- Monitor for phishing or social-engineering campaigns targeting your staff that may leverage leaked internal documentation or client correspondence for pretexting.
P3 — within 7 days
- If the vendor relationship is material, conduct a retrospective review of all data shared with Lamont Pridmore over the past 12–24 months to build a complete exposure inventory.
- Update third-party risk assessments for remaining accountancy, tax, and audit vendors to confirm they have current incident response capabilities and breach-notification contractual clauses.
5. Indicators of compromise
No indicators of compromise available in the source material. The ransomware.live listing does not provide file hashes, IP addresses, domains, URLs, email addresses, mutex names, or other atomic indicators associated with the intrusion.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Public posting of victim name and data archive on dragonforce leak site | Open-source ransomware tracking platforms (ransomware.live) | High — confirmed in source |
| 250 GB archive containing internal documentation and client financial data | Victim network / data-loss assessment (if confirmed by victim) | Low — single-sourced, unverified |
6. Detection
Insufficient indicators to author detection rules. The source material contains no file hashes, distinctive strings, command-line artefacts, mutex names, scheduled-task names, registry keys, ransom-note text, network indicators, or behavioural log signatures associated with the intrusion itself.
7. Sources
- Ransomware.live — "Ransomware: dragonforce named Lamont Pridmore (GB)" — https://www.ransomware.live/id/TGFtb250IFByaWRtb3JlQGRyYWdvbmZvcmNl — 2026-07-31
- Ransomware.live — "Ransomware: dragonforce named hive360.com" (context on dragonforce activity) — https://www.ransomware.live/id/aGl2ZTM2MC5jb21AZHJhZ29uZm9yY2U= — date not specified
8. Adverse Trace position
This is a confirmed public ransomware claim by "dragonforce" against a UK accountancy firm, but the technical detail is minimal and entirely single-sourced from ransomware.live. Attribution to "dragonforce" is unconfirmed (no MITRE ATT&CK profile exists in the verified reference data). The 250 GB data volume and the inclusion of client financial information elevate the potential impact for any EMEA financial services client that has a direct relationship with Lamont Pridmore, particularly given the firm's work in asset/wealth management, corporate finance, and tax planning. We assess the severity as moderate for the broader client base (supply-chain awareness) and high for any client with a confirmed vendor relationship with the victim. We will monitor for independent corroboration of the breach, additional dragonforce victim claims, and any emergence of technical IOCs or malware-family attribution. Clients with a direct exposure should treat this as an active third-party data-loss event and follow their incident response and third-party risk procedures.
Published via PulseTrace — Adverse Trace threat intelligence.