GLOBALMalwareProfessional ServicesProfessional ServicesRansomwareDragonforceRansom DemandedActor NamedData Leak ThreatenedData PublishedHigh
ERH
bd_16413db63bec30d5 · schema v1 · pii pii-v1
Full breach record for ERH →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group DragonForce on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Group activity: Business ServicesDiscovered: 2026-05-27
Source: Ransomware.live
Post text · scraped from the leak site
ERH is a leading provider of traffic management solutions, offering installation, maintenance and commissioning services throughout the UK.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident
No regulatory filing corroborates this yet. If an SEC 8-K, state-AG notice, or victim statement lands, DisclosureLens will merge it into an incident and link it here.
Source provenance
- Source URL
- https://www.ransomware.live/id/ZXJoLmNvLnVrQGRyYWdvbmZvcmNl
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 27, 2026
- Raw hash
- 22d6fb44b0b08d8bc1fbf8e36ddff8dce3b5cd56c041006b4ea59f46a44ee1d9
Reporting entity
- Name
- dragonforce
Victim entity
- Name
- ERHnorm: erh
- Domain
- erh.co.uk
- Industry
- Professional Servicesllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· dragonforce
- Threat actor
- DragonforceExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.