dragonforce — PABAU DATA LEAK · contactS OPEN VIA SIMPLEX · PHASE 1 ARMED
--:--:--
GROUP: dragonforce VECTOR: INTROSPECTION + WORKSTATION FOOTHOLD HAUL: 4 FILES · ≈150 MB PERSISTENCE: DAY 19 TOR V3: ONLINE
OWNED

We didn't stop at your data.
We checked who's in it.

An unauthenticated GraphQL introspection endpoint gave us the map. A forgotten support-team workstation gave us the house. Nineteen days later: 4 files, ≈150 MB, 479,555 verified emails — enriched, cross-referenced, mirrored. We're still reading. Scroll down. Take your time.

Until the full dump goes public
05:00:00:00
publication schedule — three stagesdump date:
PHASE 1 Institutional notifications. Every .gov.uk, .nhs.uk, .ac.uk, parliament.uk, police.uk address in the dump receives a personal heads-up — plus their CISO, their DPO, and their local press.
PHASE 2 The full email list goes wide. 479,555 addresses — indexed and searchable — plus the tenant shame list with booking configs and embedded phone numbers.
PHASE 3 Everything, everywhere, forever. Full 150 MB dump + OSINT enrichment report + schema documentation + permanent archive snapshot. There is no phase 4. There is no undo.
Operational status — live SIGNAL: ALIVE

Dead man's switch — armed

24:00:00

If this page goes dark, is edited, or the signal drops for 24 hours, Phase 3 fires automatically across all mirrors. Taking the page down starts the clock.

Session persistence — day 19

00:00:00 since last sync
heartbeat OK — no tampering detected

Mirror network7/8 online

dragonforce_message.txt READ ONLY

TO THE PLATFORM TEAM.

01.Introspection isn't hacking — it's asking your API to describe itself. Yours answered without asking who we were. 808 root queries later, we knew the platform better than your own interns. That gave us the map.

02.Then someone gave us the house. A support-team workstation — one credential-stuffed account, one machine that hadn't seen a patch since spring — and nineteen days of quiet access. Long enough to walk out with ≈150 MB without triggering a single alert. We left the coffee mug exactly where it was.

03.PASSWORD_RESET_AUTH: 480,177 records served open — user IDs 63 to 16,366,091 pinned to emails. You built a public index of every human with an account and called it "password reset". Then we took 2,160 permission groups with 11-area bitmasks, and 4,865 live user IDs via notification toggles.

04.And we did the thing you didn't plan for: we read the dump like journalists would. We counted the judges. We counted the police. We counted the NHS trusts. We counted the embassies. Scroll down — we made you a list. It's long.

05.Here's what we do with it: your client list is now our client list. Every tenant, every enterprise contact, every admin — we can reach the exact people who pay you, before you can warn them. Ask yourself who they'll blame when the calls start coming from "your platform".

06.Negotiation channel is below. SimpleX only — no email, no phone, no contact forms, no intermediaries. First contact within 72 hours or phase 1 fires early. Bring your CISO. Bring a decision-maker, not a lawyer.

— dragonforce

ransom_demand.txt READ ONLY
65.0000 BTC ≈ $5,000,000
bc1qtd8ll6s4dfdwgv2darvnf7us0938xzqkwnlqx2
BTC only. One address. Confirmations must clear before each phase deadline. Partial payments are ignored.
price rises in --:-- attempts: 0

+0.5% per hour until phase 1. After each phase, ×2. Time works for dragonforce.

Negotiation — SimpleX only

No email. No phone. No contact forms. SimpleX — no identifiers, no metadata, no servers that log. One-time link below. It expires when phase 1 fires.

First message: proof of the dump (your choice of table sample)
Second message: the enrichment summary — the one below
Third message: the price. It does not go down. It only goes up.
Ghost us, and every phase fires on schedule.

Complete inventory — 4 files, 150 MB

exfil_2024/

Key statistics — count them slowly

verified · deduped · cleaned

Sensitive & notable findings — deep OSINT scan

enrichment_report.txt

We didn't stop at extraction. We cross-referenced every one of the 24,154 domains against public records. What follows is who, exactly, was trusting you with their email. Certain names are held in reserve for the negotiation table. The pattern has not been held back — because the pattern is the problem.

OSINT When a clinic-platform breach stops being "a privacy incident" and starts being a national-security awkward conversation. Every category below exists in the dump. Every count is verified. Phase 1 delivers each category to its own institution's security team — with their names on the cover page.
0
NHS emails across 66 trusts — including Great Ormond Street
0
UK government emails across 69 bodies — councils, MoJ, FCDO, DHSC
0
Police officers — Met, Sussex, Herts, South Wales, Avon & Somerset
0
Parliament + judiciary — including a sitting UK judge
Categories of concern — sorted by embarrassment

Government & public sector

  • Trafford Council300 employees registered on the platform
  • Luton Council140 employees
  • Ministry of Justice7 staff · CPS1 · Irish Courts Service — 1
  • FCDO2 diplomats: ████████, ████████
  • DHSC2 staff · UKHSA2 · MHRA2
  • UK Parliament4 staff (Commons, Lords, Scottish Parliament)
  • HHJ ██████████████ — a sitting UK judge, on ejudiciary.net
  • Metropolitan Police2 officers: ██████████@met.police.uk, ████████████@met.police.uk
  • Sussex / Hertfordshire / South Wales / Avon & Somerset4 officers, emails in dump
  • Plus: Leeds, Brent, Liverpool, Surrey, Stirling councils · Environment Agency · 60+ other bodies
⚑ A sitting judge and six police officers registered on a beauty-clinic booking platform. Phase 1 writes that sentence to their press offices. Exactly like that.

International government & military

  • US State Department1 American diplomat: █████@state.gov
  • US Navy (civilian) — 1: █████@us.navy.mil
  • French Ministry of Culture1: ██████@culture.gouv.fr
  • WHO2 employees · IOM (UN Migration)1
  • ESA (European Space Agency)1 · Bank of England1
⚑ Three flags, three languages, one file list. International incident territory — at minimum, a very uncomfortable FOI request.

NHS & healthcare

  • 885 NHS emails across 66 organisations
  • Great Ormond Street Hospital · St George's · South London & Maudsley
  • Manchester University NHS FT · NHS Lothian · NHS Wales · dozens more
⚑ 66 trusts. One platform. Zero authentication required to enumerate them.

Academia — 1,534 from 259 institutions

  • Oxford211 (Saïd Business School: 154, Innovation Oxford: 57)
  • UCL53 · Bristol49 · Queen's Belfast81
  • KCL38 · LSE16
  • Plus Imperial, Leeds, Liverpool, Southampton — 250+ institutions total

Corporate & finance

  • Big Tech101 employees: Google, Apple, Meta, Microsoft, Amazon, LinkedIn, Spotify, Salesforce, Oracle, Adobe
  • Banking79: HSBC, Barclays, NatWest, Lloyds, Credit Suisse, Santander, JPMorgan, Goldman Sachs
  • Big 4160+: PwC alone: 142 — the largest single corporate presence outside Pabau itself. Deloitte 28, KPMG 19, Accenture 11
  • MBB12: McKinsey 3, BCG 3, Bain 6 — including Bain's chairman, ████████████
  • Pharma79: AstraZeneca, GSK, Roche, Novartis, J&J, Merck, Amgen, Bayer, BMS, Lilly, Gilead

Law, media, luxury & Pabau itself

  • Magic Circle60+ lawyers: Linklaters 14, Clifford Chance 11, A&O 9, DLA Piper 7, Kirkland 6, plus White & Case, Slaughter and May, Freshfields, Hogan Lovells
  • Media179: BBC 17, ITV 10, The Times 1 columnist (████████████)
  • Luxury28: Hermès, Dior, Louis Vuitton, Gucci, Burberry
  • Sports — Premier League 1, MCC / Lord's 1
  • Pabau itself1,540 @pabau.com accounts · 318 real staff (firstname.lastname format) · ~130 Balkan-origin surnames mapping heavily to North Macedonia, Kosovo, Albania (Krasniqi, Avdullahu, Brahimi, Berisha, Ademaj, Shala, Gashi, Bytyqi)
⚑ Your own org chart, self-published. We know where your dev team lives. You should probably know that about us too — you don't.

Geography — we know where your users sleep

by domain TLD
.nhs.uk · .gov.uk · .ac.uk inside a clinic-platform leak. Phase 1 delivers each institution its own slice of the file, personally addressed.