News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
black iphone 5 on yellow textile

When a listener even asks if I’m covering this news, I know it’s in the conversation.

DragonForce actors have targeted vulnerabilities in the SimpleHelp remote monitoring and management tool to launch attacks against managed service providers and their customers. In a recent incident, a threat actor exploited these vulnerabilities to deploy DragonForce ransomware, which included exfiltrating sensitive data and using double extortion tactics. The Sophos Managed Detection and Response team reported that the attackers took advantage of several vulnerabilities, including multiple path traversal and privilege escalation issues, which were disclosed (and addressed) in January 2025. Sophos has indicated that they were able to thwart the ransomware attempt for one client that utilized their endpoint protection, while other clients of the managed service provider were impacted. Sophos has since engaged in digital forensics and incident response to address the situation.

The rise of DragonForce follows their involvement in high-profile retail breaches in the United Kingdom, including attacks on Marks & Spencer and Co-op, where significant customer data was compromised. As DragonForce expands its ransomware-as-a-service model, it is quickly establishing itself as a major player in the cybercrime landscape.

Why do we care?

This is a textbook case of why the fundamentals still matter—patching, segmentation, detection—and why “low-key” RMM vendors continue to be high-risk entry points in the MSP ecosystem. The fact that this attack was executed using known vulnerabilities (disclosed in January) reinforces a grim truth: disclosed and patched threats become weaponizable when IT hygiene slips.

However, the real story may not be SimpleHelp itself, or even the specific attack vector. The real “why do we care” lies in DragonForce’s evolution as a threat actor—from disruptive ransomware player to full-blown ransomware-as-a-service (RaaS) operator executing highly coordinated, targeted extortion campaigns against both providers and end customers.

DragonForce is showing strong operational growth: high-profile retail breaches (Marks & Spencer, Co-op), RaaS sophistication, and now targeted attacks against tools used widely by SMB-focused MSPs.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories