A ransomware group has listed RÉSO on its leak site. RÉSO is a family-owned French distributor of interior-fitout building materials with operations in Morocco. The group says it has published about 676GB of internal data for free download since 7 October 2026. QPulse names the group as DragonForce. The group also claims it encrypted RÉSO's entire network, including nearly 8TB of Veeam backups, and says no agreement was reached with the company. None of the available sources is primary. RÉSO has not made a public statement, and no regulator or CERT filing has been published. Fuites Infos says explicitly that no other source has confirmed the encryption claim. Readers should treat the encryption and the attribution as the attacker's claims, not as established facts.
What Happened
There are two separate events in this story, about five weeks apart.
3 September 2026: data put up for sale. A user calling themselves "caustic" posted on a Tor-based cybercrime forum, offering data they said came from RÉSO's internal network. Both Fuites Infos and FrenchBreaches report the same figures: about 675GB, roughly 43,000 folders and around 530,000 files. The seller published the full folder tree and one employee's user directory as a sample. FrenchBreaches rates the claim as "credible."
7 October 2026: listing on a ransomware leak site. A ransomware group added RÉSO to its leak site and made about 676GB available for download. QPulse names the group as DragonForce and says it detected the listing at 22:59 UTC on 7 October. Fuites Infos covers the same listing but refers only to "a ransomware group." The group says it:
- stole confidential data on customers, partners and employees
- encrypted the whole network, including nearly 8TB of Veeam backup data
- failed to reach a deal with RÉSO
The sources don't explain how the two events are connected. The September sale and the October leak are almost the same size (675GB vs 676GB), which suggests they are the same dataset. However, no source says whether caustic is a DragonForce affiliate, an initial access broker, or someone unrelated whose data was later reused. The size match points to a link but does not prove one.
What Was Taken
Each outlet has a slightly different total. The September forum post is reported at 675GB by both Fuites Infos and FrenchBreaches. The October leak-site listing is reported at 676GB by both QPulse and Fuites Infos. The 1GB gap is most likely rounding or packaging differences.
Fuites Infos analysed the published folder tree. It says the tree covers RÉSO's office file shares and the personal folders of about 220 employee accounts across 29 sites. The analysis indicates the data includes:
- HR records: payroll, employment contracts, sick-leave records, identity documents and bank details
- Finance: accounting and invoicing
- Commercial: customer and supplier files, quotes, orders and price lists (FrenchBreaches also lists these)
- Technical: plans and technical documents linked to construction projects (FrenchBreaches)
The main risk falls on employees. Identity documents combined with bank details are enough for identity fraud and payroll-diversion scams. Customer and supplier data, including pricing and quotes, can be used for invoice fraud and business email compromise against RÉSO's partners. All of these findings are based on folder trees and samples, not on a full forensic review of the data.
Why It Matters
Backups targeted. If the claim about nearly 8TB of encrypted Veeam backups is true, this is the standard ransomware approach: take away the victim's ability to recover, then demand payment. Veeam backup servers are a common target because they often sit on the domain, store credentials, and can be reached from the production network.
Mid-sized firms are exposed. RÉSO is a mid-sized, family-owned business spread across 29 sites. Companies like this rarely have a 24/7 security operations centre, but they still hold large amounts of employee personal data and partner pricing.
Signs of earlier warning. QPulse cites a ParanoidLab exposure report that found 542 passwords and 9 session cookies linked to RÉSO. Data like this usually comes from infostealer infections. This is a single third-party data point that only QPulse reports, and no source connects those credentials to this intrusion. Even so, it is the kind of early indicator that monitoring for exposed credentials is designed to catch.
Data sold twice. The data was first offered for sale privately and then released for free. Anyone who missed the September sale can now download it. The risk to affected employees and partners grows from here.
A note on the source set. Five of the eight sources supplied for this brief cover unrelated incidents: the ASOS push-notification extortion attributed to the "Xuanye Group" (Rapid7, DIGIT, Rescana), the Aesto Health breach affecting 9.5 million patients (BleepingComputer), and the Resorttrust website intrusion (MarketScreener). None of them mentions RÉSO or DragonForce, so nothing from them is used here. The only overlap is a general one: the ASOS incident is another example of attackers going public to put pressure on a victim.
The Attack Technique
Initial access is unknown. FrenchBreaches says the entry point was not disclosed, so it cannot yet say whether it was a compromised account, an exposed service or an exploited vulnerability. The infostealer credentials ParanoidLab found (via QPulse) are a plausible lead but have not been confirmed as the entry point.
The claimed sequence of events fits DragonForce's usual double-extortion approach:
- Explore the internal network. Caustic's own post describes an "exploration" of the network.
- Copy large amounts of data from the file shares.
- Find and encrypt the backup repositories.
- Encrypt production systems.
- Publish the data on the leak site after talks fail.
No source provides indicators of compromise, malware samples or details of how the attackers moved through the network.
What Organizations Should Do
- Isolate and harden backups. Keep immutable or air-gapped copies, for example Veeam hardened Linux repositories or object lock. Remove Veeam servers from the production domain and use dedicated credentials with MFA for backup administration.
- Watch for infostealer exposure. Subscribe to credential-leak monitoring for your corporate domains. When a hit comes in, reset the password, revoke active sessions and investigate the infected device. Stolen session cookies can bypass MFA.
- Reduce data spread in file shares. Payroll records, ID scans and bank details should not live in general office shares or personal folders. Apply data classification, least-privilege access and retention limits.
- Detect large-scale exfiltration. Alert on unusually large outbound transfers, use of rclone, MEGA or similar tools, and bulk access to file shares. Hundreds of gigabytes don't leave a network without traffic someone can detect.
- Monitor underground forums for your organisation's name. RÉSO's data was openly for sale five weeks before it appeared on the leak site. Finding that listing early is an opportunity to start incident response before encryption happens.
- Prepare for fraud aimed at partners. If you are a RÉSO customer or supplier, check any changes to bank details by calling a known contact, and expect phishing that uses real quotes and invoices.
Sources: Dragonforce Ransomware Group Targets RÉSO, Exfiltrating 676GB of Da... | The ASOS incident: When attackers use the channels ... | Aesto Health says data breach affects over 9.5 million patients | Réso : fuite revendiquée de 675 Go de fichiers internes du groupe —... | Réso piraté : 675 Go de données internes et 530 000 fichiers revend... | Hackers message app users in alleged Asos data breach | Resorttrust : Apology and Notice Regarding Personal Data Leak Cause... | ASOS Data Breach 2026: Cybersecurity Incident Analysis of Third-Par...