ctipilot.ch

IFAGE Geneva — DragonForce leak-site claim (850 GB)

incident · incident:ifage-geneva-dragonforce-leak-claim-2026-07 single-source

DragonForce listed the Fondation pour la formation des adultes à Genève (IFAGE), a Geneva adult-education foundation, on its extortion leak site on 2026-07-14, claiming 850 GB of exfiltrated data — a claim exceeding and unconfirmed against IFAGE's own May 2026 disclosure of a narrower April 2026 employee-data-exfiltration incident (Inside IT, 2026-07-14; La Télé, 2026-05-15). Treated as an unconfirmed watch item.

Coverage timeline
3
first 2026-07-14 → last 2026-07-26
Peak priority
high
2 high · 1 notable
Sources cited
14
14 hosts
Sections touched
2
active-threats, legacy-strategic
Co-occurring entities
1
see Related entities below
ATT&CK techniques
5
pinned v19.2 · see below
2026-07-143 appearances2026-07-26

ATT&CK techniques

5 techniques observed across 3 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-19/weekly-w29-ch-eu-public-sector-ci-incidents · ATT&CK page ↗

T1199Trusted Relationship×2

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-26/weekly-w30-ch-eu-public-sector-third-party-incidents · 2026-07-19/weekly-w29-ch-eu-public-sector-ci-incidents · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-26/weekly-w30-ch-eu-public-sector-third-party-incidents · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×2

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-07-26/weekly-w30-ch-eu-public-sector-third-party-incidents · 2026-07-19/weekly-w29-ch-eu-public-sector-ci-incidents · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-07-14/dragonforce-leak-claim-ifage-geneva-adult-education · ATT&CK page ↗

Story timeline

  1. 2026-07-26Swiss and European public-sector bodies carried the week's home-region incident load — and nearly every one was reached through a third party, a shared platform or a fiduciary, then followed by a disclosure that had to be walked back
    legacy-strategicSwiss public-sector breaches and Romania's land registry share a shape — third-party access, and a 'not affected' claim the leak later contradicted
  2. 2026-07-19Swiss and European public-sector, utility and transport organisations carried the week's home-region incident load — a land registry offline for days, two Swiss utilities/foundations hit through third parties, an EU transit ransomware and a EUR 1.7M telco enforcement
    legacy-strategicW29 home-region incidents — ANCPI Romania offline for days, IWB Basel and Geneva's IFAGE breached, Metro Mondego ransomware, Wind Tre fined EUR 1.7M
  3. 2026-07-14DragonForce lists Geneva's IFAGE adult-education foundation on its leak site, claiming 850 GB — an attribution and volume IFAGE has not confirmed
    active-threatsDragonForce claims 850 GB from Geneva's IFAGE, layering an unconfirmed extortion listing onto a narrower April breach the foundation already disclosed

Where this entity is cited

  • legacy-strategic2
  • active-threats1

Source distribution

  • 20min.ch1 (7%)
  • autismuslink.ch1 (7%)
  • campeaoprovincias.pt1 (7%)
  • garanteprivacy.it1 (7%)
  • go4it.ro1 (7%)
  • helpnetsecurity.com1 (7%)
  • ictjournal.ch1 (7%)
  • inside-it.ch1 (7%)
  • other6 (43%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (14)

Entries about IFAGE Geneva — DragonForce leak-site claim (850 GB) (3)

2026-07-26 · view entry permalink →

HIGHNATOB1

Swiss and European public-sector bodies carried the week's home-region incident load — and nearly every one was reached through a third party, a shared platform or a fiduciary, then followed by a disclosure that had to be walked back

The week's confirmed incidents with a direct Swiss or European home-region nexus landed almost entirely on public-sector and critical-infrastructure bodies, and two structural patterns are more useful to defenders than any single victim.

The first is the access path: the breach rarely started inside the named victim. Swiss rolling-stock manufacturer Stadler Rail disclosed that the Everest group compromised a data-exchange platform it shares with a supplier and demanded CHF 10 million, which the company did not pay — "Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht", while its own production ran normally (swissinfo.ch, 2026-07-21). A Vaud fiduciary breach claimed by BravoX published more than 100,000 client files — some 220 GB — exposing tax and administrative records of roughly fifteen Nord-Vaudois municipalities and the personal tax file of a sitting cantonal State Councillor (Le Temps, 2026-07-22). A Bern autism-support foundation, Stiftung Autismuslink, confirmed that "grössere Datenmengen" were exfiltrated and its server temporarily encrypted (Stiftung Autismuslink, 2026-07); the INC Ransom RaaS group claimed the attack via a matching leak-site listing (Ransomware.live, 2026-07-24), and the foundation's constituency-relevance is that it serves Swiss cantonal education-directorate and disability-insurance-linked clients. In each case the sensitive public-sector data sat with a supplier, a fiduciary or a small third-party service organisation, not on a government perimeter.

The second pattern is a disclosure that had to be walked back. Geneva's IFAGE adult-education foundation had earlier framed its incident as affecting employee data; the attackers — the DragonForce group (ICTjournal, 2026-07-17) — published the stolen set, which included identity-document photographs, addresses and multi-year student exam results, and 20 minutes reported the disclosure "concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etc.)" (20 minutes, 2026-07-24). The starkest reversal is Romania's national land registry ANCPI, which stated on 2026-07-20 that its databases "have not been affected"; the national cybersecurity directorate DNSC's interim report describes attackers compromising the authentication servers, entering VMware vCenter, enumerating all 1,083 virtual machines, deleting roughly 100 and encrypting ESXi hosts, and exfiltrating about two million ePayment-platform user records — "nume; e-mailuri; identificatori; hash-uri ale parolelor" (PS News relaying DNSC, 2026-07-24), with the report also noting the affected servers ran no antivirus.

Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht

swissinfo.ch 2026-07-21

atacatorii au extras aproximativ două milioane de înregistrări privind utilizatori ai platformei de plăți, care conțineau: nume; e-mailuri; identificatori; hash-uri ale parolelor

PS News (relaying the DNSC report) 2026-07-24

Leur divulgation par les cybercriminels concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etc.).

20 minutes

Builds on: 2026-07-22/everest-ransomware-stadler-rail-supplier-platform-breach · 2026-07-24/bravox-vaud-fiduciary-municipalities-breach · 2026-07-25/stiftung-autismuslink-bern-inc-ransom-breach · 2026-07-14/dragonforce-leak-claim-ifage-geneva-adult-education · 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach

synthesis26 Jul 23:44Zmulti-sourceOpen finding ↗

2026-07-14 · view entry permalink →

NOTABLEupdatedNATOC3

DragonForce lists Geneva's IFAGE adult-education foundation on its leak site, claiming 850 GB — an attribution and volume IFAGE has not confirmed

The German-title source reads "the DragonForce group claims to have captured 850 gigabytes of data from IFAGE; the foundation had already warned of a leak of sensitive data." IFAGE (Fondation pour la formation des adultes à Genève), a Geneva adult-education foundation, disclosed in May 2026 that it suffered an intrusion on 11–12 April 2026 (detected 13 April): unauthorized exfiltration of current- and former-employee data, no ransom demand recorded at the time, reported to the Federal Data Protection and Transparency Commissioner, and described by IFAGE as resolved (La Télé, 2026-05-15). On 14 July 2026, Swiss IT outlet Inside IT reported that the extortion group DragonForce has now listed IFAGE on its leak site, claiming 850 GB — an order of magnitude beyond the scope IFAGE described, and a specific actor attribution IFAGE itself never made (Inside IT, 2026-07-14). No IFAGE statement responding to the listing, and no second independent outlet corroborating the DragonForce name or the 850 GB figure, could be located as of this run.

Die Gruppe Dragonforce will 850 Gigabyte an Daten von Ifage erbeutet haben. Die Stiftung hatte bereits vor einem Abfluss sensibler Daten gewarnt.

Inside IT Switzerland 2026-07-14

Des données usuelles de collaborateurs ont été compromises

La Télé 2026-05-15

Des photos de pièces d'identité, des adresses e-mail et postales, ainsi que des numéros de téléphone ou encore des résultats d'examens ont été publiés.

Leur divulgation par les cybercriminels concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etc.).

20 minutes
Updaterun 2026-07-26T1308Z-auditevidencesectorssourcesbody

The DragonForce listing against IFAGE — the Fondation pour la formation des adultes à Genève — is no longer an unverified leak-site claim. The group carried out its threat and published the data, which Le Temps reported had been done as of Thursday 2026-07-23: "Des photos de pièces d'identité, des adresses e-mail et postales, ainsi que des numéros de téléphone ou encore des résultats d'examens ont été publiés." — identity-document photographs, e-mail and postal addresses, telephone numbers and examination results (20 minutes, 2026-07-24). The same report states that their disclosure by the cybercriminals "concerne tant des employés de l'institut que des bénéficiaires (étudiants, entreprises, etc.)" — it covers both the institute's employees and its beneficiaries, meaning students and companies. It also cites an expert consulted by Le Temps who put the exposure at thousands of documents spanning several years and running to 2026. ICTjournal had reported the extortion threat a week earlier (ICTjournal, 2026-07-17).

The operationally interesting part is the gap between the victim's scoping and the published set. IFAGE's earlier public account of its incident placed the impact on employee data rather than student or pedagogical records; the leak contains multi-year examination results for students. First coverage flagged that the group's claimed volume already exceeded the institute's own disclosure, and publication has now settled that discrepancy in the attackers' favour. Nothing in the reporting identifies the initial-access vector, so no access-path lesson is available from this incident.

Contradiction: the sources and the victim do not agree on whether a ransom was ever demanded, and this entry does not resolve it. 20 minutes frames the publication as the consequence of an unpaid demand — "Si la rançon demandée n'était pas payée, les pirates informatiques qui s'en sont pris en avril à l'Ifage (Fondation pour la formation des adultes à Genève) promettaient de mettre en ligne les données dérobées" — while also reporting the foundation's own position that "La fondation avait aussi affirmé qu'elle n'avait pas reçu de demande de rançon, mais que, le cas échéant, elle refuserait de payer": it had received no ransom demand, but would refuse to pay if one came (20 minutes, 2026-07-24). ICTjournal is more definite on the demand's existence, reporting a week earlier that a ransom was now being demanded and that the group threatened to publish at the expiry of the ultimatum posted on its leak site (ICTjournal, 2026-07-17). A leak-site ultimatum naming a ransom the victim says never reached it is a common pattern and not necessarily either party misspeaking — demands are frequently posted publicly rather than delivered.

incident14 Jul 20:22Zsingle-sourceOpen finding ↗

2026-07-19 · view entry permalink →

HIGHNATOB2

Swiss and European public-sector, utility and transport organisations carried the week's home-region incident load — a land registry offline for days, two Swiss utilities/foundations hit through third parties, an EU transit ransomware and a EUR 1.7M telco enforcement

The home-region incident load this week fell almost entirely on public administration, utilities and transport — the profiled constituency's core — and split into three recognisable shapes.

Direct public-sector disruption. Romania's National Agency for Cadastre and Real Estate Publicity (ANCPI) — the authority running the national land-registry and cadastre systems (e-Terra, RENNS) used by citizens, notaries and banks — had all IT systems offline from 14 July after a confirmed cyberattack; a data-leak operator using the alias ByteToBreach (tracked by KELA) claims to have stolen citizen data and the e-Terra/RENNS source code from a copied GitLab server, deployed ransomware and begun deleting backups, which ANCPI disputes (Help Net Security, 2026-07-16). Portugal's Metro Mondego confirmed a 6 July ransomware attack on internal systems — claimed by TheGentlemen — that its IT/OT separation kept off the Metrobus service, a clean example of segmentation limiting blast radius (Campeão das Províncias, 2026-07-17).

Swiss organisations hit through their suppliers. The Basel canton utility IWB (electricity, gas, water, telecom) disclosed that a compromised external service provider exfiltrated ~40,000 customer meter records (names, addresses, meter numbers) — IWB's own systems and supply were unaffected and the Basel-Stadt data-protection officer assessed misuse risk as low (Netzwoche, 2026-07-15). Geneva adult-education foundation IFAGE was listed by DragonForce claiming 850 GB, layered onto a narrower April breach it had already disclosed — single-sourced and unconfirmed, a watch item rather than an established breach.

Enforcement and cross-border tax-data exposure. Italy's Garante fined Wind Tre EUR 1,715,600 with an unusually complete technical account: retail-staff vishing led to valid MFA'd access, then a pivot from a protected primary API to an unprotected secondary API and ~2 million sequential customerId requests exfiltrating 365,048 customers (Garante, 2026-07-16). Ernst & Young separately disclosed a third-party ITSM-platform breach exposing client tax data.

Builds on: 2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach · 2026-07-16/iwb-basel-third-party-provider-breach-40k-customer-records · 2026-07-14/dragonforce-leak-claim-ifage-geneva-adult-education · 2026-07-18/metro-mondego-thegentlemen-ransomware-portugal-transit · 2026-07-17/garante-wind-tre-vishing-api-enumeration-fine · 2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data · 2026-07-17/abacus-erp-unauth-rce-path-traversal-ncsc-ch

synthesis19 Jul 23:50Zmulti-sourceOpen finding ↗