Rosello et Fils Ransomware Claim by Eclipse (Sep 2026)
Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.
Leak Site Screenshot
Screenshot captured at time of discovery. Image blurred to protect victim PII.
Claim Summary
On or around September 14, 2026, the ransomware group known as Eclipse allegedly added Rosello et Fils to its dark web leak site. Rosello et Fils is a fruit and vegetable wholesaler headquartered in Saint-Laurent-Blangy, France, reportedly operating for over 100 years and serving professional clients across the Hauts-de-France region, including the Nord, Pas-de-Calais, and Somme departments.
According to the threat actor’s leak site post, the company’s client base purportedly includes commercial and collective catering operations, local shops, and large and medium-sized retail surfaces. The group has not disclosed a data volume, which is unusual and may indicate either a limited exfiltration set or an attempt to inflate perceived severity without evidence. No sample files, screenshots, or proof-of-compromise artifacts have been publicly referenced in the claim text itself.
This claim has NOT been independently verified by Yazoul Security or any third party. It remains a single unconfirmed assertion from a criminal actor.
Threat Actor Profile
The group operating as Eclipse is a relatively low-profile ransomware operation. Based on currently available intelligence, Eclipse has no confirmed public research references, no documented tooling, and no verified victim count. This is a significant credibility gap.
Unlike established operations such as LockBit, ALPHV, or Cl0p, which have well-documented affiliate structures, leak site histories, and tooling signatures, Eclipse presents almost no observable tradecraft in open sources. That absence could mean the group is new, is a rebrand of a prior operation, or is simply a low-volume actor that has not attracted researcher attention. It could also mean the claim is opportunistic or fabricated.
No known tools, malware families, or YARA rules can be attributed to Eclipse at this time. Detection guidance is therefore limited. Organizations in the food distribution sector should rely on general ransomware hygiene: endpoint detection and response (EDR) coverage, immutable backups, network segmentation, and monitoring for unusual data staging or outbound transfer activity.
Alleged Data Exposure
The leak site post allegedly describes Rosello et Fils’ business profile but does not specify a data volume, file count, or data categories. No samples have been observed. The actor claims the victim operates exclusively within Hauts-de-France and serves catering, retail, and shop clients.
If the claim is genuine, plausible exposure could include client contracts, pricing agreements, supplier records, logistics data, and employee information. However, none of this has been confirmed. The lack of any published proof is a notable weakness in the claim’s credibility.
Potential Impact
For a regional food wholesaler, a genuine ransomware incident could disrupt order processing, cold chain logistics, and delivery scheduling. Clients in catering and retail depend on reliable supply, so even a short outage could cause contractual friction and reputational harm.
Regulatory exposure is also relevant. Under GDPR, a confirmed personal data breach could trigger notification obligations to the CNIL and affected individuals. But again, no breach has been verified.
What to Watch For
- Whether Eclipse publishes data samples or a count, which would strengthen or weaken the claim.
- Any official statement from Rosello et Fils confirming or denying the incident.
- Whether other French food sector organizations appear on the same leak site, suggesting a targeted campaign.
- Any CNIL or regional authority notification.
Disclaimer
This report is based solely on an unverified claim posted to a ransomware group’s leak site. Yazoul Security has NOT independently confirmed the attack, the data exposure, or the actor’s identity. Ransomware groups frequently exaggerate or fabricate claims to pressure victims. Nothing here should be treated as fact. For related monitoring, see our intel hub and news coverage.
Never miss a threat intelligence alert
Get real-time security alerts delivered to your preferred platform.