Ransom! SAD’S Interim (SEP-2026)

Ransom! SAD’S Interim (SEP-2026)
The ransomware attack impacting SAD’S Interim (FR) has been attributed to the threat actor rhysida, targeting sensitive business records used in temporary employment operations, including SQL backups of the BRANIPP ERP, payroll documents, and bank-related transaction information. The compromised data also included identity and employment documentation for workers, such as SEPA bank statements, payslips, contracts, and government-issued cards/IDs. #France

Incident Details

  • Victim: SAD’S Interim
  • Sector: Professional Services
  • Country: FR
  • Actor: rhysida
  • Source: http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?company=268
  • Discovered: 2026-09-08T06:02:10.597437+00:00
  • Published: 2026-09-08T06:01:43.427807+00:00

Information

  • Since 2000, the company has established itself as a key player in the temporary employment sector.
  • Bank statements with SEPA credit transfers.
  • Factoring records, including invoice import batches, client receivables ledgers with EUR amounts and named clients, and payment receipts.
  • SQL backups of the BRANIPP ERP, the temp-workers payroll database.
  • Payslips and payroll validation workbooks.
  • Permanent-staff employment contracts signed by the owners.
  • Temp-worker contracts and Pôle Emploi attestations.
  • Passports for EU and third-country nationals.
  • CARTE BTP construction-worker cards with photo and date of birth.
  • Carte Vitale health-insurance cards.
  • RIB bank account details.
  • NIR national insurance numbers.
  • MDPH disability recognition documents.

Disclaimer: This post is based on public claims made by the ransomware group "rhysida". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live