SAD'S Interim Ransomware Claim by Rhysida (Sep 2026)
Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.
Leak Site Screenshot
Screenshot captured at time of discovery. Image blurred to protect victim PII.
Claim Summary
The Rhysida ransomware group has allegedly listed SAD’S Interim, a French temporary employment and professional services firm operating at sads-interim.eu, on its dark web leak site. According to the threat actor, the attack was purportedly carried out on 8 September 2026. The group claims to have exfiltrated a broad set of internal records, though no data volume has been disclosed and no proof has been independently reviewed by Yazoul Security.
As with all leak site postings, this remains an unverified claim. Rhysida has not provided public evidence that the data is genuine, current, or complete.
Threat Actor Profile
rhysida is a ransomware operation that surfaced in mid-2023 and is known for double extortion - encrypting victim systems while threatening to publish stolen data. The group has targeted healthcare, education, government, and manufacturing organizations across Europe and North America. Rhysida is frequently associated with the use of Cobalt Strike and other legitimate penetration testing tools for lateral movement, along with phishing and exploitation of internet-facing services as initial access vectors.
Public research on Rhysida is widely available from multiple security vendors, though no group-specific tooling details were provided in this leak site entry. Rhysida has a mixed credibility record: some claims have been substantiated by leaked samples, while others appear inflated or recycled. The group has also been observed re-listing victims and adjusting claims to increase pressure.
Alleged Data Exposure
The threat actor claims to hold a wide range of sensitive records, including:
- Bank statements and SEPA credit transfer records
- Factoring documents: invoice import batches, client receivables ledgers with EUR amounts and named clients, and payment receipts
- SQL backups of the BRANIPP ERP, described as the temp-worker payroll database
- Payslips and payroll validation workbooks
- Permanent-staff employment contracts signed by the owners
- Temp-worker contracts and Pole Emploi attestations
- Identity documents: passports, CARTE BTP cards, carte Vitale cards, RIB bank details, NIR national insurance numbers, and MDPH disability recognition documents
If genuine, this would represent a severe exposure of both corporate financial data and personal data belonging to employees and temporary workers. However, none of this has been verified, and ransomware groups routinely exaggerate the scope and sensitivity of stolen data.
Potential Impact
The alleged data set combines financial records, payroll systems, and identity documents. If confirmed, potential consequences could include:
- Regulatory exposure under GDPR, given the presence of NIR numbers, identity documents, and health-related records
- Fraud and identity theft risk for affected workers
- Business disruption from ERP and payroll system compromise
- Reputational and contractual damage with clients and staffing partners
These are hypothetical risks based on the group’s unverified claims, not confirmed outcomes.
What to Watch For
- Independent confirmation from SAD’S Interim or French authorities
- Whether Rhysida publishes sample files as proof
- Notification obligations under GDPR and CNIL guidance
- Any follow-on phishing or fraud targeting affected individuals
- Whether the listing is removed, suggesting a possible negotiation
Disclaimer
This report is based solely on an unverified claim published by the Rhysida ransomware group. Yazoul Security has not independently confirmed the attack, the authenticity of any data, or the accuracy of the group’s statements. Ransomware operators frequently misrepresent victim data to pressure organizations. Nothing here should be treated as established fact. Affected parties should consult qualified legal and incident response professionals.
Never miss a threat intelligence alert
Get real-time security alerts delivered to your preferred platform.
Related Claims
Tower View Primary School — rhysida
General Santos Doctors Hospital — rhysida
Agencia Estatal de Meteorología — Panzer
Air Canada — thegentlemen