DragonForce leaks WinFashion ERP client data
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
DragonForce ransomware group posted a 73GB data dump from B2B fashion ERP provider WinFashion, exposing payment code, source code, and PII for ~40 brands.
Ransomware.live's victim-tracking page documents a DragonForce ransomware group leak attributed to WinFashion Technologies, a Los Angeles-based B2B ERP provider (WF125sR / Fabric ERP V.10) serving over 250 fashion brands with integrations to Shopify, JOOR, NuORDER, CommerceHub, and FashionGo. The published dump totals roughly 205,000 files and 73GB, with analysts flagging over 125,000 files (61%) as at-risk, including 9,350 classified as critical exposure.
Key exposed material includes a 5.64GB full MSSQL backup of a client's ERP instance (Customer/Style Master, EDI, AR data), six SSL PFX certificate containers plus an EDI-VAN client certificate for ECGrid/OpenText, over 33,000 WinSCP SFTP session logs, 332 ASP.NET Web.config files potentially containing hardcoded Shopify/Authorize.Net secrets, 171 files with payment card data tied to Authorize.Net processing code, and 39 files with IBAN/SWIFT bank account details. Also exposed: 40,621 EDI transaction files covering the B2B trade lifecycle, aggregated product catalogs, vendor/customer lists, HR/payroll data, and substantial intellectual property — 8,577 C# integration source files, 5,828 PowerBuilder ERP core files, and legacy unencrypted DBF/MDF database tables.
This represents a cross-tenant B2B SaaS incident with downstream exposure for roughly 40 fashion brand clients, raising PCI DSS, CCPA/CPRA, GDPR, and SEC Regulation FD concerns. Defenders at organizations integrating with WinFashion or using its ERP/EDI services should assume credential and certificate compromise, rotate any Shopify/Authorize.Net API keys or secrets shared with this vendor, review EDI/VAN certificates for reuse, and monitor for fraudulent use of exposed payment processing code or bank account data.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/d2luZmFzaGlvbkBkcmFnb25mb3JjZQ==
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 9,768 reports from 155 sources, 1,535 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs