EPLS: Entreprise d'Installations électriques Courant Fort Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
EPLS, the French electrical-installation firm, was listed today by the Qilin ransomware group, which claims to have stolen internal files. If you have worked with EPLS, check whether your data may have been exposed and take appropriate protective steps.
Ransomware groups continue to pressure suppliers that support critical infrastructure, using data theft and public leak-site listings to force negotiations. On 8 September 2025 the group known as qilin publicly listed EPLS, a French electrical-installation firm that works on high- and low-voltage systems for airports, hospitals, data centres and other essential facilities. The listing asserts that internal files were taken in a ransomware attack; the number of people affected remains unknown and further technical detail has not been released. Because EPLS sits inside supply chains that keep major public services running, the claim warrants careful attention even while many specifics stay unconfirmed.
Inside the incident
Public reporting on 8 September 2025 states that qilin added EPLS (full name Entreprise d'Installations électriques Courant Fort) to its leak site. The group claims internal files were exfiltrated during a ransomware attack. No confirmed figures have been published for the volume of data, the precise date of intrusion, the initial access method, or the number of individuals whose information may have been involved. The available summary notes only that the company designs and builds high-voltage and low-voltage electrical systems for a broad service sector that includes airports, hospitals, data centres and other critical infrastructure in France. Beyond the leak-site claim itself, independent verification of the breach’s scope or success has not been supplied in the record. Timing of any encryption event, ransom demand, or subsequent data publication remains undisclosed.
The group behind it: qilin
Qilin is a ransomware-as-a-service operation that has been active in the public threat landscape for several years. Like many contemporary groups, it typically combines encryption of victim systems with theft of data, then threatens to publish the material on a dedicated leak site if payment is not made. Affiliates often handle initial access and deployment while the core operators manage negotiations and the leak infrastructure. Public reporting has linked qilin to attacks across manufacturing, professional services and infrastructure-related firms in multiple countries. In this case the group claims to have listed EPLS after exfiltrating internal files; that assertion originates from the leak site and has not been independently corroborated in the available facts. No statements attributed to qilin beyond the listing itself appear in the record for this incident.
About EPLS
EPLS is a French enterprise specialising in the design and construction of high-voltage and low-voltage electrical installations. Its clients and projects span the large service sector, notably airports, hospitals, data centres and other critical infrastructure across France. Organisations of this type routinely hold engineering drawings, project schedules, supplier contracts, site access information and operational documentation that support the continuous functioning of those facilities. A compromise at such a firm can therefore raise questions not only about the company’s own operations but also about potential knock-on effects for the infrastructure it helps maintain. The truncated public summary indicates that EPLS takes pride in its role in these sectors, underscoring the sensitivity of the environments in which it works.
What data was at risk
The facts state that internal files were exfiltrated in the ransomware attack. No further breakdown of file types, categories or volumes has been disclosed, and the number of people affected is listed as unknown. Companies engaged in electrical design and construction for critical infrastructure typically maintain project plans, technical specifications, employee records, client correspondence, procurement data and site-related documentation. Whether any of those categories were among the files claimed by qilin cannot be confirmed from the public record. Exact contents therefore remain unconfirmed; only the general description “internal files” is available.
Why it matters
For individuals whose personal or professional information may have been stored in EPLS systems, the principal risks include potential misuse of contact details, credentials or identity documents if such material was present, as well as targeted phishing that references genuine project or workplace context. For the organisation itself, loss of proprietary engineering data or operational documents can disrupt project delivery and require costly remediation. Because EPLS supports airports, hospitals and data centres, any exposure of access procedures or system layouts could, in theory, inform further reconnaissance against those facilities; no evidence of such secondary use has been reported. The absence of confirmed victim counts or data inventories means the precise scale of harm cannot yet be measured, yet the critical-infrastructure context elevates the need for careful monitoring by both the company and its partners.
If your data was in this claimed breach
If you have reason to believe your information was held by EPLS, begin by monitoring financial and email accounts for unusual activity and enable multi-factor authentication wherever it is available. Change passwords that may have been reused across work and personal services, and remain alert to phishing messages that reference electrical projects, airports, hospitals or data-centre work. Consider placing fraud alerts with relevant credit agencies if identity documents could have been involved. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan provides an additional, independent signal while official notifications, if any, are still pending.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
GROUPE ETMB Listed by qilin Ransomware GroupTF LE TOIT FOREZIEN Listed by qilin Ransomware GroupRoger RENARD Entreprise Listed by qilin Ransomware GroupBuldi Listed by qilin Ransomware GroupLatest breaches
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.