# DragonForce leaks WinFashion ERP client data

Published: 2026-09-24 · Severity: high · Sectors: retail, technology, manufacturing
Canonical: https://vorant.io/reports/a60a0883-717d-58c4-9228-1d97ae37f7fa/dragonforce-leaks-winfashion-erp-client-data

> DragonForce ransomware group posted a 73GB data dump from B2B fashion ERP provider WinFashion, exposing payment code, source code, and PII for ~40 brands.

Ransomware.live's victim-tracking page documents a DragonForce ransomware group leak attributed to WinFashion Technologies, a Los Angeles-based B2B ERP provider (WF125sR / Fabric ERP V.10) serving over 250 fashion brands with integrations to Shopify, JOOR, NuORDER, CommerceHub, and FashionGo. The published dump totals roughly 205,000 files and 73GB, with analysts flagging over 125,000 files (61%) as at-risk, including 9,350 classified as critical exposure.

Key exposed material includes a 5.64GB full MSSQL backup of a client's ERP instance (Customer/Style Master, EDI, AR data), six SSL PFX certificate containers plus an EDI-VAN client certificate for ECGrid/OpenText, over 33,000 WinSCP SFTP session logs, 332 ASP.NET Web.config files potentially containing hardcoded Shopify/Authorize.Net secrets, 171 files with payment card data tied to Authorize.Net processing code, and 39 files with IBAN/SWIFT bank account details. Also exposed: 40,621 EDI transaction files covering the B2B trade lifecycle, aggregated product catalogs, vendor/customer lists, HR/payroll data, and substantial intellectual property — 8,577 C# integration source files, 5,828 PowerBuilder ERP core files, and legacy unencrypted DBF/MDF database tables.

This represents a cross-tenant B2B SaaS incident with downstream exposure for roughly 40 fashion brand clients, raising PCI DSS, CCPA/CPRA, GDPR, and SEC Regulation FD concerns. Defenders at organizations integrating with WinFashion or using its ERP/EDI services should assume credential and certificate compromise, rotate any Shopify/Authorize.Net API keys or secrets shared with this vendor, review EDI/VAN certificates for reuse, and monitor for fraudulent use of exposed payment processing code or bank account data.

## Mentioned in this report

- Threat actors: DragonForce
- Malware: DragonForce

Source reporting: https://www.ransomware.live/id/d2luZmFzaGlvbkBkcmFnb25mb3JjZQ==

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a60a0883-717d-58c4-9228-1d97ae37f7fa/dragonforce-leaks-winfashion-erp-client-data.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
