Skip to content
Leak-site post naming Dediserve Ltd, captured by ThreatCluster

Dediserve Ltd

n0n

Ransomware leak-site victim intelligence · EN

Posted
Sep 28, 2026
Country
Ireland / Germany
Industry
Cloud infrastructure provider

Summary

Written by ThreatClusterfrom victim profile, leak post

The group n0n claims to have taken the complete FRA1 cloud customer register—167 tenant accounts with infrastructure details—and disk images of tenant servers, including a regulated forex broker's portal with its payment gateway configuration and trading-account records, a payment services provider's systems including its internal password vault, and a production real-estate platform. They also claim access to the provider's internal operations mailbox and monitoring configuration, and that all 46 FRA1 servers and backups have been removed; the only restore path is the disk images they say they hold. The leak page describes the victim as a cloud infrastructure provider linked to the iomart group, with FRA1 cloud operations in Dublin, Ireland and Frankfurt DC, and the publication status is countdown.

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

What was taken

The complete customer register of the FRA1 cloud — 167 tenant accounts with infrastructure details; Disk images of tenant servers: a regulated forex broker's portal (payment gateway configuration, trading-account records), a payment services provider's systems including its internal password vault, and a production real-estate platform; The provider's internal operations mailbox and monitoring configuration

Leak site tags
iomart groupFRA1 Frankfurt DC

Leak-site images (1)

Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.

ThreatCluster capture