Flashpoint A.I CyberSecurity Scoring
Flashpoint
Company Information
Website:https://www.flashpoint.io
Employees number:358
Number of followers:33,029
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:flashpoint.io
Flashpoint Risk Score (AI oriented)
Between 0 and 549
FlashpointTechnology, Information and Internet
Updated:
01/04/2026
01/04/2026
452/1000
Critical
C
Flashpoint Global Score (TPRM)
xxxx
FlashpointTechnology, Information and Internet
Score locked

FlashpointCritical
Current Score
452C (CRITICAL)
01000
3 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
492
AUGUST 2026
489
JULY 2026
482
JUNE 2026
474
MAY 2026
467
APRIL 2026
460
MARCH 2026
447
FEBRUARY 2026
436
JANUARY 2026
434
DECEMBER 2025
426
NOVEMBER 2025
548
OCTOBER 2025
406
JULY 2025
678
Ransomware
01 Jul 2025 • Flashpoint
RansomHub: Ransomware Gang Goes Full 'Godfather' With Cartel
DragonForce Ransomware Cartel Emerges as a Major Threat with Mafia-Style Tactics
364
CRITICAL-314
FLA1770252228
DragonForce Ransomware Cartel Emerges as a Major Threat with Mafia-Style Tactics
Since its launch in 2023, the DragonForce ransomware-as-a-service (RaaS) operation has rapidly evolved into a sophisticated cartel, adopting organized crime tactics to dominate the ransomware ecosystem. The group offers affiliates a full suite of tools, including customizable encryption models for Windows, Linux, and ESXi systems, with features like delayed execution, multithreading for faster attacks, and SMB port scanning to identify targets. Analysis by LevelBlue reveals that DragonForce’s code shares striking similarities with the leaked Conti ransomware source code, including the ability to delete shadow copies and optimize encryption speeds.
Beyond technical capabilities, DragonForce has embraced a cartel-style business model, encouraging cooperation among ransomware gangs to standardize tactics, eliminate competition, and maximize profits. The group provides members with petabytes of storage, 24/7 server monitoring, decryption services, and even "dry run" attack simulations along with a "Company Data Audit" service to assess stolen data’s value and craft tailored extortion strategies. To attract affiliates, DragonForce has eliminated vetting and deposit requirements, streamlining onboarding through an automated registration system.
The cartel’s aggressive expansion has included harassment of rival groups, such as defacing BlackLock’s leak site and attempting to mislead RansomHub affiliates into believing they had joined the cartel a move that prompted public accusations of collaboration with Russia’s FSB intelligence service. DragonForce’s victimology targets manufacturing, technology, business services, and construction sectors, with a focus on organizations in the U.S., UK, Italy, Germany, and Australia. As of July 2025, the group had claimed at least 250 victims via its data leak site, positioning itself as a major player in the ransomware landscape.
By fostering a unified front among cybercriminals, DragonForce exemplifies a troubling shift toward intelligence-driven extortion, where threat actors adopt consulting-like strategies to refine negotiations and increase ransom payouts. The cartel’s rise underscores the growing challenge for defenders, as shared tactics and pooled resources make these groups harder to counter.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Ransomware
01 Jul 2025 • Flashpoint
DragonForce and RansomHub: The “Godfather” of Ransomware Gangs Calls for Cooperation and Coordination
Ransomware Gangs Shift to Cartel-Like Operations, Led by DragonForce
364
CRITICAL-314
FLADRA1770281021
Ransomware Gangs Shift to Cartel-Like Operations, Led by DragonForce
The global ransomware landscape is undergoing a major transformation as cybercriminal groups adopt a cartel-like model, prioritizing collaboration over competition to strengthen attacks and ensure long-term survival. At the forefront of this shift is DragonForce, a ransomware group that emerged in 2023 and is now evolving into a highly organized criminal enterprise.
Research by LevelBlue, a Texas-based cybersecurity firm, reveals that DragonForce is actively recruiting affiliates by offering extensive infrastructure and operational support. Rather than operating as a traditional ransomware gang, the group positions itself as a service provider, lowering the technical barrier for newcomers while expanding its reach. Affiliates retain independence in developing and deploying ransomware but must share a portion of profits with DragonForce in exchange for access to petabytes of data storage, server monitoring, decryption tools, and attack testing environments.
Beyond basic ransomware-as-a-service (RaaS) offerings, DragonForce provides data audit services, allowing affiliates to assess the financial value of stolen data before launching double-extortion attacks threatening both encryption and public leaks. This model enhances the efficiency and profitability of cybercrime operations.
Recent intelligence, including a July 2025 report by Check Point Research, places DragonForce among the top ransomware groups, trailing only Akira and Qilin. The group has also engaged in aggressive tactics against rivals, including website defacements and member poaching, earning a reputation as both dominant and predatory. Some observers have dubbed DragonForce the "Godfather" of ransomware gangs, a title reinforced after rival group RansomHub accused it of collaborating with Russia’s FSB to suppress competition a claim that highlights the blurred lines between cybercrime and geopolitics.
As ransomware operations grow more centralized and sophisticated, international law enforcement agencies including those in the U.S., U.K., Italy, Germany, and Australia are facing increased pressure to dismantle these emerging cybercrime cartels before they solidify into an even more entrenched threat.
INCIDENT DETAILS -
TYPE
MOTIVATION
DATA BREACH
REFERENCES
SEPTEMBER 2024
769
Ransomware
01 Sep 2024 • Flashpoint
RansomHub, Ryuk and Black Basta: ShadowSyndicate Leverages Server Transition Technique in Latest Ransomware Attacks
ShadowSyndicate Adopts Advanced Server Rotation Tactics to Evade Detection
662
CRITICAL-107
RYUBLAFLA1770302429
ShadowSyndicate Adopts Advanced Server Rotation Tactics to Evade Detection
In February 2026, cybersecurity researchers at Group-IB uncovered a sophisticated server transition technique employed by ShadowSyndicate, a cybercrime group first identified in 2023. The threat actor has refined its infrastructure management by rotating SSH fingerprints across multiple command-and-control (C2) servers, attempting to obscure operational continuity. Despite these efforts, operational security (OPSEC) lapses such as overlapping SSH keys allowed researchers to trace connections, revealing at least 20 active C2 servers linked to attack frameworks like Cobalt Strike, Metasploit, Havoc, Mythic, and Sliver.
ShadowSyndicate’s method involves transferring servers between SSH clusters to simulate legitimate ownership changes, creating plausible deniability. However, distinct patterns in SSH key usage exposed the group’s activities. Researchers confirmed two additional SSH fingerprints tied to the group in early 2026, further mapping its infrastructure.
The group’s operations are closely tied to multiple ransomware campaigns, including Cl0p/Truebot, ALPHV/BlackCat, Black Basta, Ryuk, and Malsmoke, with varying degrees of confidence. During RansomHub attacks in September–October 2024, Darktrace observed data exfiltration to ShadowSyndicate-associated servers via SSH, specifically linking the IP 46.161.27[.]151 to their C2 infrastructure. Another server (179.60.149[.]222) was found hosting MeshAgent alongside a known SSH fingerprint.
Analysts assess with moderate confidence that ShadowSyndicate operates as either an Initial Access Broker (IAB) or bulletproof hosting (BPH) provider, leveraging a network of private European providers with ties to Russian offshore entities. These providers disguise operations as VPN or proxy services, using layered autonomous system numbers (ASNs) like AS209588 and AS209132.
The group demonstrates a consistent preference for specific hosting providers, creating predictable attribution patterns despite attempts to diversify infrastructure. Their zero-day exploitation capabilities and organization-scale resources position them as a hybrid infrastructure provider, fueling both ransomware operations and potentially state-sponsored advanced persistent threats (APTs).
As of February 2026, ShadowSyndicate’s infrastructure remains active, continuing to scan for vulnerabilities and deploy malicious payloads.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Flashpoint ??
What was Flashpoint's A.I Rankiteo Cyber Score in August 2026 ??
What was Flashpoint's A.I Rankiteo Cyber Score in July 2026 ??
What was Flashpoint's A.I Rankiteo Cyber Score in June 2026 ??
What was Flashpoint's A.I Rankiteo Cyber Score in May 2026 ??
What was Flashpoint's A.I Rankiteo Cyber Score in April 2026 ??
What was Flashpoint's A.I Rankiteo Cyber Score in March 2026 ??
What was Flashpoint's A.I Rankiteo Cyber Score in February 2026 ??
What was Flashpoint's A.I Rankiteo Cyber Score in January 2026 ??
What was Flashpoint's A.I Rankiteo Cyber Score in December 2025 ??
What was Flashpoint's A.I Rankiteo Cyber Score in November 2025 ??
What was Flashpoint's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Flashpoint's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Flashpoint ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Flashpoint's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?