Incident analysis
RÉSO was listed by Dragonforce ransomware, a group with 648 victims recorded in this database. The listing appeared on the group's leak site on October 7, 2026.
RÉSO is based in France and operates in the Technology sector. France ranks #6 worldwide for ransomware disclosures, with 563 victims in this database.
Sector context. Technology companies hold intellectual property, customer data, and source code — all highly valuable assets. A successful ransomware attack can also put downstream customers at risk through supply chain exposure.
Dragonforce typically follows a double extortion model: data is exfiltrated from the victim's systems before files are encrypted, so the victim faces two demands at once — pay to restore access, and pay to keep stolen data unpublished. The leak site, where this listing appeared, is the lever for the second demand.