Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

SAD'S Interim

sads-interim.eu

Group Rhysida
Discovered 2026-09-08 06:02 UTC
Est. attack date 2026-09-08
Country FR
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

SAD'S Interim Since 2000, SAD'S INTERIM has established itself as a key player in the temporary employment sector.Bank statements (relev�s) with SEPA credit transfersFactoring: invoice import batches, client receivables ledgers (encours) with EUR amounts and named clients, payment receipts (quittances)SQL backups of the BRANIPP ERP (the temp-workers payroll database)Payslips (bulletins de salaire) and payroll validation workbooksPermanent-staff employment contracts signed by the owners (Sadoun family)Temp-worker contracts, Pole Emploi attestationsPassports (EU and third-country nationals)CARTE BTP (construction-worker cards with photo and DOB)carte Vitale (health-insurance cards)RIB (bank account details)NIR (national insurance numbers)MDPH (disability recognition documents) More

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • sadsinterim-eu01b.mail.protection.outlook.com. Microsoft 365
TXT Records
  • @=6b4694da81085ee5fd1d160f87c4cd2f
  • www=6c6f705ae1c4931b7c8b01fc86223a01
  • v=spf1 a mx include:spf.protection.outlook.com include:spf.mailjet.com -all
  • MS=ms46484647
Cloud / SaaS Services Detected
Mailjet Microsoft 365

Leak Screenshot:

Leak Screenshot