Ransomware victim disclosure
← All victimsAdvanced Programs, Inc.
listed as advprograms.com · Claimed by Dragonforce · listed 2 months ago
Status timeline
- ListedApr 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Apr 14, 2026
About the victim
AI dossier — public-source company profileAdvanced Programs, Inc. (API) is a US-based defense and intelligence technology company founded in 1969, headquartered in Columbia, Maryland. The company designs, manufactures, and supports TEMPEST-certified and TSG-certified computing, networking, and communications products that meet stringent US and NATO security standards. Its customers include US Government agencies involved in intelligence, defense, and foreign affairs, as well as NATO and allied nations.
- Industry
- TEMPEST & Secure Communications Products / Defense Electronics
- Address
- 7125 Riverwood Drive, Columbia, MD 21046, United States
- Founded
- 1969
Attack summary
Severity: critical — Advanced Programs, Inc. is a cleared defense contractor supplying TEMPEST and secure communications products to US Government intelligence, defense, and foreign affairs agencies, and NATO. Any exfiltration of their data carries extremely high national-security implications, including potential exposure of government customers, classified program details, security certifications, personnel records, and sensitive technical documentation.DragonForce claims to have exfiltrated data from Advanced Programs, Inc. and has published the data; no ransom amount was stated and no data size was specified in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Unspecified exfiltrated company data
What the group claims
Advanced Programs, Incorporated (API) specializes in providing secure, high-quality integrated system solutions designed specifically for government and industrial clients, particularly in the fields of intelligence, defense, and foreign policy. The product portfolio includes TEMPEST-certified computers, networking equipment, and secure communication devices that meet stringent security standards. API retrofits existing products from leading manufacturers and develops new designs to ensure reliability in high-risk environments. The company’s typical customers are program management offices responsible for deploying and maintaining secure IT solutions in remote locations.
The leak post
captured from the group's site```
{"data":{"count":483,"publications":[{"uuid":"b008b8b7-0e47-416f-adcd-2313d8136de4","created_at":"2026-05-08T20:56:13.122134Z","name":"CF Evans Construction","website":"www.cfevans.com","address":"125 Regional Pkwy Ste 200, Orangeburg, South Carolina, 29118, United States","description":"A recognized leader in the multi-family housing construction industry, CF Evans Construction provides a product for developers. The company has thrived amid six decades.\nThe data of this company includes:\n Corporate correspondence of senior executives\n Financial documents\n HR documents\n Accounting documents\n Certificates, contracts, passwords, databases, and much more.","weight":4775795351552,"is_timer_publication_stopped":false,"timer_publication":"2026-05-22T07:48:00Z","try_again":false,"tags":[],"logo_uuid":"f4e582dd-6562-4590-bac8-2b9e5c564853","is_transfering":false},{"uuid":"3827192f-9bb3-490c-9c1c-d28b382510cd","created_at":"2026-05-08T17:53:24.736605Z","name":"CMC Expertise Comptable","website":"cmcexpertise.fr","address":"32 Rue De La Clairière, Fort-de-France,","description":"CMC Expertise Comptable is a certified accounting firm located in Martinique, dedicated t…Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

