Ransomware victim disclosure
← All victimsPerpetuuiti Technosoft
listed as Perpetuuiti · Claimed by Dragonforce · listed 4 months ago
Status timeline
- ListedFeb 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Country
- India
- Sector
- Technology
- Listed on leak site
- Feb 5, 2026
- Data size
- 145 MB
About the victim
AI dossier — public-source company profilePerpetuuiti (operating as Perpetuuiti Technosoft, www.ptechnosoft.com) is an India-based technology company that provides enterprise resilience and intelligent automation platforms, including disaster recovery, business continuity, RPA, and AIOps solutions. The company serves 400+ global customers across sectors such as banking, insurance, telecom, aviation, and healthcare. Its products include the Operational Resiliency Automation Platform, Continuity Patrol, Cyber Resiliency tools, and the Av3ar intelligent automation suite.
- Industry
- IT Resilience & Intelligent Automation Software
Attack summary
Severity: high — Data has been confirmed published (not merely listed), involving a technology company that handles enterprise resilience and disaster recovery for 400+ global customers; exfiltration of internal data from such a firm could expose sensitive customer configurations, contracts, or security-relevant information, though no explicit regulated PII at scale or government/defence data is confirmed.DragonForce claims to have exfiltrated approximately 145 MB of data from Perpetuuiti, with the disclosure status marked as data_published, indicating the stolen data has been released or made available on the group's leak site.
Data the group says was taken
AI dossier — extracted from the leak post- Exfiltrated company data (145 MB published)
What the group claims
An initial analysis of the structure and names of the files revealed that the directory contains software source codes, configuration and installation files, backup copies of information systems, database structures and dumps, as well as financial, administrative, operational, and technical documentation related to the functioning of the organization's IT systems. However, the presence or absence of personal data, including contact telephone numbers, cannot be reliably confirmed without additional analysis of the contents of the backups and databases, which indicates a potential area of risk in the context of data protection and information security management requirements. Listing files = 145MB.
The leak post
captured from the group's site```
{"data":{"count":483,"publications":[{"uuid":"b008b8b7-0e47-416f-adcd-2313d8136de4","created_at":"2026-05-08T20:56:13.122134Z","name":"CF Evans Construction","website":"www.cfevans.com","address":"125 Regional Pkwy Ste 200, Orangeburg, South Carolina, 29118, United States","description":"A recognized leader in the multi-family housing construction industry, CF Evans Construction provides a product for developers. The company has thrived amid six decades.\nThe data of this company includes:\n Corporate correspondence of senior executives\n Financial documents\n HR documents\n Accounting documents\n Certificates, contracts, passwords, databases, and much more.","weight":4775795351552,"is_timer_publication_stopped":false,"timer_publication":"2026-05-22T07:48:00Z","try_again":false,"tags":[],"logo_uuid":"f4e582dd-6562-4590-bac8-2b9e5c564853","is_transfering":false},{"uuid":"3827192f-9bb3-490c-9c1c-d28b382510cd","created_at":"2026-05-08T17:53:24.736605Z","name":"CMC Expertise Comptable","website":"cmcexpertise.fr","address":"32 Rue De La Clairière, Fort-de-France,","description":"CMC Expertise Comptable is a certified accounting firm located in Martinique, dedicated t…Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

