Ransomware victim disclosure
← All victimssa2000.com UPDATE-FULL DATA DUMP
Claimed by Stormous · listed 4 days ago
Status timeline
- ListedJun 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Stormous
- Status
- Data leaked
- Listed on leak site
- Jun 9, 2026
About the victim
AI dossier — public-source company profileSA2000 (sa2000.com) appears to be a commercial or trading enterprise operating with French-language business processes. Limited public information is available.
- Industry
- General Commerce / Trading
Attack summary
Severity: high — Confirmed exfiltration of 150 GB including financial records, banking data, customer/supplier information, employee records, and shareholder details. Significant operational and compliance risk despite no specific regulatory sector identified.Stormous claims to have exfiltrated approximately 150 GB of data from SA2000, including financial records, banking information, client and supplier data, and employee records. The group published the data and stated willingness to negotiate.
Data the group says was taken
AI dossier — extracted from the leak post- accounting records
- purchase invoices
- payable invoices
- modified invoices
- banking information
- customer payments
- client lists
- purchase orders
- supplier/transporter records
- employee/hiring records
- shareholder information
- email/email documents
What the group claims
150 GB of data has been extracted, including: COMPTABILITÉ - FACTURES ACHAT / FACTURES À PAYER / FACTURES MODIFIÉES - Banking Informations SA2000 - PAIEMENTS CLIENTS - CLIENTS / PO CLIENTS - FOURNISSEUR / TRANSPORTEURS - EMPLOYÉS / EMBAUCHE - ACTIONNAIRES - COURRIEL / DOCUMENTS COURRIELS.There is still an opportunity to communicate and resolve this situation. We are currently awaiting the company's !
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

