Group:
Dragonforce
Discovered by ransomware.live: 2026-04-01
Estimated attack date:
2026-04-01
Description:
Over the last 40 years, Fountain has established itself as Europe's leading supplier of drinks vending machines for businesses, delivering the widest range of solutions to organisations with 5 to 50 employees, as well as multi-site key account customers. The company now operates in 28 countries and has developed a strong reputation and identity, founded on personalised services and solutions, a wide range of tailor-made products, and a local distribution network. Here at Fountain, we provide our customers with a comprehensive service that covers cartridge and automatic machines, capsule machines, water fountains, accessories and snacks. Fountain distributes a vast range of both own-brand and third-party products. As such, it is able to meet the exacting demands of businesses and organisations looking to tailor their offer to the specific needs of their customers and/or staff, from precise quantities to consumer preferences. Fountain has been listed on the Euronext stock exchange since
DNS Records:
The following DNS records were found for the victim's domain.
- fountain-eu.mail.protection.outlook.com.
- 168lirrk2c17iqvijmob9n7cnl
- pbk198jcfjg4sr220bu6rs6fq9
- qgu2vhng3nujkhor13tauiiu4s
- btvf8du2thon2dnbd8c4jb62om
- brevo-code:dbfc8103ca10e68c07169944ba4b2bf1
- ePIW65Ud
- D3vbaVIrd3yfNdBGPdmLFzrGuJNRO9WwEVG5SLrhCcrF26BMsIHL+zZxL9exRbNSITSppdY/Qxk8FmkxyxzecQ==
- apple-domain-verification=SfeLYCPYjembIoYK
- t60inpt3vjuglncnl7kh780kbj
- MS=ms83831316
- google-site-verification=nAdnJjlZSANaEbdm0hoKexHkdV7tKyja-nQLQapT09M
- vngjnvgu9ghft7ebec5tedu2um
- google-site-verification=IjWp_nZFRpeiHw1j_f9rLXMwJfEU2_tV7Oj5WAxv-V0
- v=spf1 redirect=_s071zfyap.sdmarc.net include:145012695.spf02.hubspotemail.net
Cloud / SaaS Services Detected
Apple
HubSpot
Microsoft 365
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.