Ransomware victim disclosure
← All victimsRÉSO
Claimed by Dragonforce · listed 5 hours ago
Status timeline
- ListedOct 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Dragonforce
- Status
- Data leaked
- Country
- France
- Sector
- Technology
- Listed on leak site
- Oct 7, 2026
About the victim
AI dossier — public-source company profileRÉSO is a French distributor and partner specializing in second-fix building products and services. They supply ceilings, partitions, flooring, acoustic products, and cladding systems to construction projects across France, with multiple regional agencies.
- Industry
- Building Materials & Interior Finishes Distribution
Attack summary
Severity: low — Post contains only a malformed API request with no proof of data access, exfiltration, encryption, or impact. Does not constitute a credible attack announcement.The leak post contains only a single API error message (400 Bad Request from an internal blog endpoint). No data exfiltration, encryption, or operational disruption is claimed or evidenced.
What the group claims
Réso specializes in secondary works, offering a wide range of products including ceilings, partitions, floors, technical floors, and facades. They provide modular and dry partitions, acoustic products, and various accessories, ensuring a comprehensive solution for construction needs. With numerous agencies across France and a team of specialists trained in the latest innovations, Réso serves a diverse clientele with thousands of available products. Their commitment to quality and service is reflected in their partnerships and significant projects. 676 GB of confidential information about their customers, partners, employees were stolen. The entire network was locked including nearly 8TB of Veeam backups. The company has failed to reach for an agreement.
The leak post
captured from the group's site[GET] "http://blog-main_backend.local:2000/api/guest/blog/post?post_uuid=e7424f37-2786-42d1-a413-a7c88a8b1796": 400 Bad Request
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

