Desk live·
ForensicPost
Ransomware/Method/File 25-0602b

They Looked at the Customer List Before Deciding Anything

Having reached the provider, the operators used its management platform to enumerate customers — device names, configurations, users, network connections — before deploying anything.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
TargetMSP customer estates
ActorDragonForce
S. Rosler11 min readConfidence: high2 sources reviewed

After reaching the provider, the operators used its management platform to perform reconnaissance across customer systems, collecting device names and configurations, user accounts and network connection details before deploying encryptors.

The Platform Was Better Reconnaissance Than Any Intrusion

An attacker inside a single organisation must map it while avoiding detection — the expensive, noisy phase this desk described at 25-0611, where a stolen network diagram converts a future intrusion from exploration into navigation.

A management platform does that work as a feature. It holds an accurate, current, indexed inventory of every customer estate, because managing them requires one.

The reconnaissance was not an intrusion technique. It was reading a dashboard.

Which Turns The Attack Into A Selection Problem

With a customer list and configuration detail, an operator can choose which downstream organisations to hit — by size, by sector, by apparent backup posture, by whichever looks most likely to pay.

The corpus filed at 25-1125 that the 102-day Nevada dwell was the operation, and the deployment was the last act. Here the equivalent preparation took reading rather than moving, which compresses the window in which anyone could notice.

And It Means The Downstream Victims Were Chosen

The corpus normally records supplier incidents where every downstream customer is affected because their data sat in one place — Marquis at 25-0814, Chain IQ at 25-0613.

This is different. The customers were not incidentally exposed; they were surveyed and picked. Whichever organisations were not encrypted were spared by a decision, not by a control.

How we reported this

Compiled from published vendor research, listed below. The selection criteria used by the operators are not established and are not asserted here. Corrections: corrections@forensicpost.com.

Sources
  1. DragonForce ransomware abuses SimpleHelp in MSP supply chain attackBleepingComputer
  2. What recent ransomware campaigns teach MSPs about supply chain securityLevel
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary