Ransomware victim disclosure
← All victimsGelatissimo
listed as gelatissimo.com.au · Claimed by Dragonforce · listed 2 months ago
Status timeline
- ListedApr 27, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Country
- Australia
- Sector
- Hospitality and Tourism
- Listed on leak site
- Apr 27, 2026
About the victim
AI dossier — public-source company profileGelatissimo is Australia's leading artisanal gelato brand, operating over 60 retail locations across Australia and expanding internationally through a master franchise program. The company produces fresh gelato daily in-store across more than 40 flavours, including dairy-free, reduced-sugar, and vegan options. It is headquartered in Rydalmere, New South Wales, and operates a franchise model seeking major investors in retail and franchising.
- Industry
- Artisanal Gelato Retail & Franchising
- Address
- Unit 6, 9-11 South Street, Rydalmere, New South Wales, 2116, Australia
Attack summary
Severity: high — Data has been confirmed as published (~378 GB exfiltrated), indicating significant exfiltration of business data from a franchise operation that likely includes franchisee PII, financial records, and corporate correspondence, though no confirmed large-scale regulated personal data (e.g. medical or government) is evidenced.DragonForce claims to have exfiltrated approximately 378 GB of data from Gelatissimo, with the data published on the group's leak site. The disclosed status indicates data has been published, though no specific ransom amount was stated.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate data
- Franchise-related documents
- Business correspondence
- Financial records
- Investor/partner information
What the group claims
A global brand seeking major investors with experience in retail and franchising to expand its artisanal ice cream chain through a master franchise program
The leak post
captured from the group's site```
{"data":{"count":483,"publications":[{"uuid":"b008b8b7-0e47-416f-adcd-2313d8136de4","created_at":"2026-05-08T20:56:13.122134Z","name":"CF Evans Construction","website":"www.cfevans.com","address":"125 Regional Pkwy Ste 200, Orangeburg, South Carolina, 29118, United States","description":"A recognized leader in the multi-family housing construction industry, CF Evans Construction provides a product for developers. The company has thrived amid six decades.\nThe data of this company includes:\n Corporate correspondence of senior executives\n Financial documents\n HR documents\n Accounting documents\n Certificates, contracts, passwords, databases, and much more.","weight":4775795351552,"is_timer_publication_stopped":false,"timer_publication":"2026-05-22T07:48:00Z","try_again":false,"tags":[],"logo_uuid":"f4e582dd-6562-4590-bac8-2b9e5c564853","is_transfering":false},{"uuid":"3827192f-9bb3-490c-9c1c-d28b382510cd","created_at":"2026-05-08T17:53:24.736605Z","name":"CMC Expertise Comptable","website":"cmcexpertise.fr","address":"32 Rue De La Clairière, Fort-de-France,","description":"CMC Expertise Comptable is a certified accounting firm located in Martinique, dedicated t…Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

