ADULLACT Listed by fog Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ADULLACT was listed by the fog ransomware group on February 13, 2025, with internal files reported as exfiltrated; the date of the actual intrusion has not been established. Anyone who may have shared data with ADULLACT should review the organisation’s notices and consider changing passwords or enabling extra account protections.
On February 13, 2025, the French association ADULLACT appeared on a listing by the fog ransomware group, which claimed to have carried out a ransomware attack involving the exfiltration of internal files. Public detail remains limited: the number of people affected is unknown, and no further confirmation of the incident's scope or method has been disclosed beyond the group's claim and a brief summary noting the association's role. The listing matters because ADULLACT develops and promotes free software used by local authorities and public administrations, meaning any compromise could touch systems and data linked to government operations at the municipal and administrative level.
What is known so far rests on the reported claim of internal-file exfiltration rather than on independently verified technical findings. No dollar amounts, file counts, or precise timelines beyond the reporting date have been made public, leaving the full picture incomplete for those who may rely on ADULLACT's tools or services.
Breaking down the breach
The incident is described as a ransomware attack in which internal files were allegedly exfiltrated. ADULLACT was listed by the fog ransomware group on or around February 13, 2025. Beyond that date and the characterization of the data as internal files, public sources provide no Reported Details on how the attackers gained access, whether encryption was also deployed, how long the intrusion lasted, or the volume of material taken. The number of individuals potentially affected is listed as unknown. The only additional contextual note available is a short extract linking ADULLACT to free-software development for French local authorities and administrations, alongside mentions of related entities Omydoo and Ayomi, though the precise connection of those names to the breach itself is not elaborated. In short, the core facts are the listing itself, the claim of ransomware-driven exfiltration of internal files, and the absence of further quantified or technical disclosure.
Inside fog
Fog is a ransomware group that has operated publicly by listing victims on dedicated leak sites, a common practice among contemporary ransomware actors who combine system encryption with data theft to pressure targets. Public reporting on the group describes a typical double-extortion model: after gaining access, operators exfiltrate files and then threaten to publish them if a ransom is not paid. Fog has been observed targeting organizations across multiple sectors rather than specializing in a single industry, and its listings often appear with limited technical proof until or unless data samples are released. The group is known for claiming responsibility through these dark-web postings rather than through direct public statements to media. In this case, the listing of ADULLACT constitutes the group's claim that it conducted the attack and obtained internal files; no independent confirmation of that claim is contained in the available facts, and no specific statements by fog about ADULLACT's systems or negotiations have been reported. Readers should treat the leak-site entry as an unverified assertion until further evidence surfaces.
ADULLACT and its sector
ADULLACT is a French association whose stated purpose is to develop and promote a repository of free and open-source software intended for use by local authorities and public administrations. Organizations of this type typically maintain code repositories, documentation, user accounts for developers and civil servants, project-management records, and sometimes integration details for municipal IT environments. Because the software is aimed at government bodies, ADULLACT sits at the intersection of the open-source community and the public sector. A breach involving such an association is consequential for two reasons: first, any compromise of internal files could expose operational information about software used in official settings; second, trust in free-software tools for public administration depends on the integrity of the organizations that curate them. Even without confirmed large-scale personal-data exposure, the incident raises questions about the security of the supply chain that supports local-government digital services in France.
The information in question
The facts name the exposed material only as "internal files exfiltrated in a ransomware attack." No further breakdown—such as source code, user databases, financial records, or personal identifiers—has been disclosed. Organizations like ADULLACT commonly hold source-code repositories, contributor and administrator credentials, internal correspondence, project roadmaps, and configuration details for software deployed by municipalities. Whether any of those categories were among the files taken remains unconfirmed. Because the people-affected count is listed as unknown, it is also unclear whether personal data belonging to staff, volunteers, or end users of the software was included. Exact contents are therefore unconfirmed; the only established description is the generic label of internal files.
What's at stake
For individuals whose contact details, credentials, or project contributions might appear in internal files, the practical risks include targeted phishing, credential stuffing against other services, or social-engineering attempts that reference genuine project names. For the association itself, the stakes involve potential disruption of software-maintenance workflows, reputational damage among the local authorities that rely on its repository, and the cost of forensic investigation and remediation. Public administrations that depend on ADULLACT-maintained tools could face secondary concerns if configuration data or integration details were among the exfiltrated material, though no such specifics have been confirmed. In concrete terms, the incident creates uncertainty rather than proven mass exposure: people and institutions must weigh the possibility of misuse of internal documents against the limited public evidence currently available.
What to do if you're exposed
If you have worked with ADULLACT, contributed code, or used accounts linked to its services, begin by changing passwords on any related accounts and enabling multi-factor authentication where available. Monitor email and financial accounts for unusual activity, and treat unsolicited messages that reference ADULLACT projects with caution. Because the precise data types remain unconfirmed, a measured approach—updating credentials and staying alert—is more useful than assuming the worst. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets, providing an additional early-warning step while official details continue to be limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
VISEO Listed by fog Ransomware GroupOmydoo Listed by fog Ransomware GroupThe 19 biggest gitlabs Listed by fog Ransomware GroupMelexis Listed by fog Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the ADULLACT Listed by fog Ransomware Group →
Publicly posted by fog — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.