DragonForce Claims Attack on One Community FCU, Alleges Member Data Stolen
A ransomware group has listed a US credit union on its dark-web site, claiming to hold internal files and member financial records. The credit union has not confirmed any incident.

Key points
- DragonForce, a ransomware criminal group, listed One Community Federal Credit Union on its dark-web leak site on 21 July 2026.
- The group claims to hold member financial records, internal documents, and data allegedly tied to a third-party security firm.
- One Community FCU has not publicly confirmed any breach as of publication, and the claim could not be independently verified.
- Ransomware leak-site listings are written by the attackers themselves to pressure victims into paying, and are sometimes exaggerated or false.
- Customers should watch for scam calls and fake emails that use this news as cover.
A criminal group calling itself DragonForce added One Community Federal Credit Union, a US-based member-owned financial institution, to its dark-web leak site on 21 July 2026. The listing was observed by Ransomware.live, a service that monitors these criminal postings.
Ransomware, for readers unfamiliar with the term, is malicious software that criminals use to lock or steal a company's files, then demand payment to return them. Leak sites are pages these groups run to publicly name companies and publish stolen data as extra pressure to pay.
The group's post claims to have obtained databases, internal documents, and client financial records from One Community FCU. It also names a Baton Rouge-based firm it says handled security work for the credit union, suggesting that firm's work contributed to the alleged breach. Those claims come directly from the attackers and have not been verified.
One Community FCU has not issued any public statement about the incident. No public confirmation exists, and Threat Vectr has not been able to verify the claim independently.
Should credit union members be worried right now?
Not necessarily, but caution costs nothing while the facts remain unclear. Criminals routinely use news of an alleged breach, confirmed or not, to launch follow-up scams. If you hold an account with One Community FCU, here is what to do while this claim remains unconfirmed.
Watch your inbox for phishing emails, meaning fake messages designed to look like they come from the credit union or from a regulator, asking you to click a link or hand over account details. Be equally wary of phone calls claiming to offer "breach compensation" or asking you to verify personal information. Those calls are almost always scams.
If you use the same password for your credit union account as you do for email, social media, or other financial sites, change it. Use a different password for each account. Most phones and browsers now offer a free built-in password manager to help.
The credit union's own website or official app will be the first place a genuine notification appears if the institution confirms anything. Check there directly rather than following links in emails or texts.
DragonForce has claimed attacks against multiple organisations this year. Listings like this one sometimes precede a company's public disclosure by days or weeks. They are also sometimes exaggerated or entirely false. The regulatory picture will sharpen if One Community FCU files a disclosure with a federal regulator, which would trigger formal notification timelines under applicable US financial services rules. No such filing is publicly visible at this time.



