Marc Dorcel Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Marc Dorcel was listed by the Qilin ransomware group on 22 March 2026, confirming that internal files had been exfiltrated. Individuals who may have had dealings with the company are advised to monitor their accounts and consider additional protective steps.
What happened
The only confirmed detail is the appearance of Marc Dorcel on qilin’s leak site. The listing asserts that files were removed from the company’s systems. No timeline for the intrusion, no volume of data, and no confirmation of encryption or further demands have been made public.
Inside qilin
Qilin is a ransomware-as-a-service operation that has been active for several years. The group typically gains access through compromised credentials or remote services, deploys encryption, and maintains a leak site to publish samples of stolen material when victims do not pay. Its targets have included entities across multiple industries; the decision to list a victim is presented by the group as evidence that negotiations failed.
Marc Dorcel and its sector
Marc Dorcel is a French company that produces and distributes adult entertainment content. Organizations in this sector maintain customer accounts, subscription records, payment information, and internal operational files. A public claim of data theft therefore raises questions about both customer privacy and the confidentiality of business records.
What was likely exposed
The listing refers only to “internal files.” The exact categories of data have not been disclosed. Companies of this type commonly store customer identifiers, contact details, transaction histories, and proprietary content files, yet none of these have been verified in the present case.
- Internal documents referenced in the listing
- No confirmed customer or employee records
- Scale and sensitivity remain unverified
Why it matters
Publication of internal material can expose business practices and any personal information contained in those files. Individuals whose data appears in such records may face risks of targeted fraud or unwanted disclosure. For the organization, the incident adds operational costs and potential regulatory scrutiny even when the full scope is still unknown.
If your data was in this claimed breach
Monitor financial accounts and email for unusual activity. Enable multi-factor authentication on any services linked to the company. Review privacy settings on accounts that may share data with third parties. Readers can run a free exposure scan of their email address against known breach repositories to check for prior appearances of their information.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Viviany Listed by qilin Ransomware GroupTrace Listed by thegentlemen Ransomware GroupSarl Alliance Listed by qilin Ransomware GroupGoodwill Manasota Listed by Qilin RansomwareLatest breaches
Read GalaxyWarden’s full analysis of the Marc Dorcel Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.