Ransomware victim disclosure
← All victimsFountain
Claimed by Dragonforce · listed 2 months ago
Status timeline
- ListedApr 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Country
- Belgium
- Listed on leak site
- Apr 1, 2026
About the victim
AI dossier — public-source company profileFountain is a Belgian B2B company specialising in turnkey workplace coffee break solutions, serving over 20,000 businesses ranging from SMEs to large multisite enterprises. Its services include design and installation of customised coffee corners, supply of coffee machines and water dispensers, consumables delivery, and ongoing maintenance. The company also operates an online webshop for business clients.
- Industry
- Workplace Coffee & Water Solutions (B2B Beverage Services)
Attack summary
Severity: medium — Data is stated as published by DragonForce, confirming exfiltration; however, no specific sensitive data categories (PII at scale, financial records, medical, etc.) are enumerated in the available leak post excerpt, and the victim is a mid-market B2B services company, limiting assessed severity to medium.DragonForce claims to have exfiltrated data from Fountain and has published the data; the leak post indicates disclosed status of 'data_published' though the specific data categories and volume are not enumerated in the available excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate data (nature unspecified in excerpt)
What the group claims
Over the last 40 years, Fountain has established itself as Europe's leading supplier of drinks vending machines for businesses, delivering the widest range of solutions to organisations with 5 to 50 employees, as well as multi-site key account customers. The company now operates in 28 countries and has developed a strong reputation and identity, founded on personalised services and solutions, a wide range of tailor-made products, and a local distribution network. Here at Fountain, we provide our customers with a comprehensive service that covers cartridge and automatic machines, capsule machines, water fountains, accessories and snacks. Fountain distributes a vast range of both own-brand and third-party products. As such, it is able to meet the exacting demands of businesses and organisations looking to tailor their offer to the specific needs of their customers and/or staff, from precise quantities to consumer preferences. Fountain has been listed on the Euronext stock exchange since
The leak post
captured from the group's site```
{"data":{"count":483,"publications":[{"uuid":"b008b8b7-0e47-416f-adcd-2313d8136de4","created_at":"2026-05-08T20:56:13.122134Z","name":"CF Evans Construction","website":"www.cfevans.com","address":"125 Regional Pkwy Ste 200, Orangeburg, South Carolina, 29118, United States","description":"A recognized leader in the multi-family housing construction industry, CF Evans Construction provides a product for developers. The company has thrived amid six decades.\nThe data of this company includes:\n Corporate correspondence of senior executives\n Financial documents\n HR documents\n Accounting documents\n Certificates, contracts, passwords, databases, and much more.","weight":4775795351552,"is_timer_publication_stopped":false,"timer_publication":"2026-05-22T07:48:00Z","try_again":false,"tags":[],"logo_uuid":"f4e582dd-6562-4590-bac8-2b9e5c564853","is_transfering":false},{"uuid":"3827192f-9bb3-490c-9c1c-d28b382510cd","created_at":"2026-05-08T17:53:24.736605Z","name":"CMC Expertise Comptable","website":"cmcexpertise.fr","address":"32 Rue De La Clairière, Fort-de-France,","description":"CMC Expertise Comptable is a certified accounting firm located in Martinique, dedicated t…Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

