Ransomware victim disclosure
← All victimsAgiliance
listed as agiliance.fr · Claimed by ZaWoo · listed 7 hours ago
Status timeline
- ListedSep 24, 2026
- Data leakeddate unknown
At a glance
- Group
- ZaWoo
- Status
- Data leaked
- Country
- France
- Sector
- Professional Services
- Listed on leak site
- Sep 24, 2026
About the victim
AI dossier — public-source company profileAgiliance is a French accounting and business advisory group formed by the consolidation of 8 small-to-medium-sized accounting firms operating across the Haute-Saône and Doubs regions. The group serves over 2,000 clients and offers comprehensive services including accounting, taxation, HR, legal, audit, and business management consulting while maintaining a local, client-focused approach.
- Industry
- Accounting & Business Advisory Services
- Address
- Multiple locations: Lure, Luxeuil-les-Bains, Roche-lez-Beaupré, Saint-Loup-sur-Semouse, Saône, Vesoul, Maîche, Pontarlier (Haute-Saône and Doubs, France)
- Employees
- 105
Attack summary
Severity: medium — Data published by the group with disclosed status confirmed, but no specific proof count or detailed inventory of sensitive data categories provided in the leak post. Given the nature of accounting firms handling client financial and tax information, the exposure is moderate in sensitivity but lacks concrete evidence documentation.ZaWoo claims to have compromised Agiliance and published data. The leak post does not specify the nature of the compromise (encryption, exfiltration, or both) or detail the specific data categories at stake.
Data the group says was taken
AI dossier — extracted from the leak post- Client financial records
- Accounting data
- Business advisory information
What the group claims
Agiliance is a French accounting and business advisory group headquartered across the Haute-Saône and Doubs regions. Its website describes Agiliance as the result of bringing together 8 small-to-medium-sized accounting firms, combining their expertise and tools while retaining a local, client-oriented approach.
Sources
Source
Indexed 7 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

