RÉSO Ransomware Claim by DragonForce (Oct 2026)
Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.
Leak Site Screenshot
Screenshot captured at time of discovery. Image blurred to protect victim PII.
Claim Summary
On or around October 7, 2026, the ransomware group known as DragonForce allegedly listed the French technology and construction services company RÉSO on its dark web leak site. According to the threat actor, the group claims to have stolen 676 GB of confidential information relating to customers, partners, and employees. DragonForce further alleges that it locked the entire network, including nearly 8 TB of Veeam backups, and that the company has failed to reach an agreement.
This claim has NOT been independently verified by Yazoul Security. It remains an unverified assertion published by a criminal extortion group.
Threat Actor Profile
dragonforce is a ransomware operation that has been tracked across multiple regions in recent years. The group is generally assessed to operate with a ransomware-as-a-service style model, though public research on its internal structure remains limited. No public research references were available for this specific actor at the time of writing.
Known tools and tactics for DragonForce are not well documented in open sources. Based on industry reporting, the group has been associated with double extortion techniques, exfiltrating data before deploying encryption. Some reporting has linked the group to the use of legitimate remote monitoring and management tools, as well as common credential theft and lateral movement techniques. However, Yazoul Security cannot confirm specific tooling for this incident.
Given the absence of a well-documented track record, the group’s credibility should be treated with caution. Ransomware groups routinely exaggerate the scope and sensitivity of stolen data to increase pressure on victims. The claim of 676 GB and 8 TB of backups may be inflated.
Alleged Data Exposure
According to the threat actor, the allegedly stolen data includes confidential information about RÉSO’s customers, partners, and employees. The group claims the entire network was locked, including nearly 8 TB of Veeam backups. RÉSO is described as specializing in secondary works, including ceilings, partitions, floors, technical floors, and facades, with numerous agencies across France.
Yazoul Security has not reviewed any data samples and cannot confirm the volume, contents, or authenticity of the alleged exfiltration. No download links, credentials, or data samples are included in this report, in line with our editorial policy.
Potential Impact
If the claim is accurate, the exposure of customer, partner, and employee information could create regulatory obligations under French and EU law, including GDPR notification requirements. Business operations could be disrupted if backups were indeed encrypted. However, these are hypothetical impacts based on an unverified claim.
What to Watch For
- Official statements from RÉSO or its representatives.
- Any notification from French data protection authorities (CNIL).
- Independent confirmation of data exfiltration from third-party researchers.
- Changes to the leak site post, which may indicate negotiation or removal.
Disclaimer
This report is based solely on an unverified claim published by a ransomware group. Yazoul Security has NOT independently verified the attack, the data theft, or the volume of data allegedly stolen. Ransomware groups frequently exaggerate claims. Nothing in this report should be treated as fact. Organizations should rely on official statements and independent forensic analysis. For related coverage, see our /news/ section.
Never miss a threat intelligence alert
Get real-time security alerts delivered to your preferred platform.
Related Claims
The Galliher Law Firm — dragonforce
Primius Law Firm — dragonforce
BMGP Groupe — dragonforce
Owen Leigh Optometry — dragonforce