Home All Victims Downes

Downes

dragonforce

This record tracks a ransomware attack claimed by the dragonforce group against Downes. It collects the publicly disclosed attack details — sector, location and timeline — as published on the operator's leak site and indexed by Breach House.

Window Zero

EXPOSURE GAP

Window Zero is the time the breach stayed in the open before anyone said so — the gap between when the attack was first discovered on the operator's leak site (t1) and when it was publicly disclosed (t2). The wider this window, the longer victims, staff and customers were exposed with no warning.

248days open
t1 · Published t2 · Pending
Oct 10, 2025Not disclosed yet
Country
Australia
Business Category
Retail / E-commerce
Employees
0-50
Discovered
2025-10-10
Published
October 10, 2025
Disclosed / Notified
Not disclosed yet
Victim ID
CpHggwYrYWYa

Attack Summary

Proudly managing FMCG brands for over 35 years. With over 94% coverage of the major grocery retailers, Downes services Woolworths, Coles, Independent Supermarkets (including IGA & Foodworks), Bunnings, Big W and Priceline. ​ We have the ability to manage products from development stage, all the way through the submission phase right up to ranging on shelves. With extensive experience in FMCG sales, merchandising and planogram implementation across all retailers Downes is a valuable resource that can be utilised for your brand in the Australian marketplace. ​ In addition to all the major retailers that Downes services, we also have the ability to buy/sell products into each state and territory with our direct to store model for independent retailers. Where supply via the Metcash DC is not an option Downes can give brands a much greater reach with our team of full time sales reps servicing this channel on a regular call cycle. ​ Downes is a business who truly values honesty, integrity and transparency. We are a passionate, loyal business who deliver on our promises.

Leak Screenshots

SAMPLE

Proof-of-breach screenshots the operator posted from the stolen data. Previews are redacted and locked — the originals are available on HaveIBeenRansom.

file_tree.png
finance_2024.xlsx
passport_scan.jpg
contract_signed.pdf
Sign in or explore HaveIBeenRansom to view the full leak gallery.
View leak gallery →

Dark Web Exposure

Cross-referenced against HaveIBeenRansom's dark-web index of ransomware leaks, breaches & infostealer logs.
0
found in Infostealer logs
0
found in Traditional breaches
0
found in Ransomware leaks
Emails exposed
••••
Internal
•••
External
•••
Distinct leaks
••
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
••••••••••••••••••••••••
•••••••••• · ••••••
••• emails
Full exposure is locked
See every breached email, the internal-vs-external split and each leak source behind this victim.
Want the complete picture — passwords, machines, full leak files? It's all searchable on HaveIBeenRansom.
Search this victim →
Visit Website Original Post View Group: dragonforce
Legal Disclaimer: This ransomware victim record reflects information published on the operator's leak site. Breach.house does not acquire, download, host, access or redistribute unlawfully obtained data. It indexes only publicly visible information posted by ransomware, breach and infostealer operators and open web sources, without accessing the underlying stolen content. The service supports public awareness, legitimate research and cyber-resilience.