Rosello et Fils Listed by Eclipse Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Rosello et Fils was listed by the Eclipse ransomware group on 14 September 2026, with the group claiming to hold data from an undisclosed number of individuals. Anyone who may have had dealings with the organisation should check their accounts and consider protective steps.
On September 14, 2026, the ransomware group known as Eclipse listed Rosello et Fils on its leak site. That listing is an unverified claim by the group. As of writing, Rosello et Fils has not publicly confirmed that an incident occurred, that systems were accessed, or that any data left its control. In today’s threat landscape, leak-site postings are a common pressure tactic: crews name organisations, threaten publication, and invite attention before any independent verification exists. Readers should treat the claim as an allegation until the company, a regulator, or another authoritative source speaks to it.
Rosello et Fils is a named, identifiable business. Repeating an unproven accusation as settled fact would mislead people who rely on clear information. What follows summarises what the public listing is said to assert, what remains undisclosed, and what practical steps make sense if personal or business data were ever involved—without treating the crew’s marketing as an inventory of what was taken.
Inside the listing
According to the listing attributed to Eclipse, Rosello et Fils appears among organisations the group has named on its leak site. The reported date associated with that appearance is September 14, 2026. Public detail in the material provided does not describe how access was supposedly obtained, whether ransomware was deployed, whether a ransom demand was made, or whether any files were copied or published. The number of people potentially affected is unknown. Data types supposedly involved are not disclosed in the available summary.
Leak-site entries of this kind are claims controlled by the actors who run them. They can be incomplete, recycled, exaggerated, or false. Nothing in the facts supplied confirms exfiltration, encryption, downtime, or contact with customers or suppliers. The company has not, on the information available for this article, issued a public confirmation of the incident. Until such confirmation or independent reporting exists, the responsible framing is that Eclipse has listed the firm—not that a breach has been established as fact.
The group behind it: Eclipse
Eclipse is known publicly as a ransomware and extortion-style actor that uses leak sites to name organisations and apply pressure. Groups in this category typically claim to have taken data, threaten staged release, and mix technical disruption with reputational leverage. Public reporting on such crews often describes double-extortion patterns: encryption paired with alleged theft, followed by countdown-style publication threats. Those are general patterns associated with this class of actor; they are not proof of what happened in any single unconfirmed listing.
For this specific case, the only claim that should be attributed to Eclipse is the listing of Rosello et Fils itself and whatever sparse description accompanies it on the crew’s site. The facts provided here do not include quotes from Eclipse about file volumes, sample dumps, or technical methods unique to this victim. Where those details are absent, they remain undisclosed. Treating the group’s broader reputation as a substitute for evidence about this organisation would overstate what is known.
About Rosello et Fils
Rosello et Fils is described as a fruit and vegetable wholesaler based in Saint-Laurent-Blangy, France. Public-facing descriptions of the business note more than a century of experience and operations focused on the Hauts-de-France region, serving professionals in the Nord, Pas-de-Calais, and Somme departments. Its client base is said to include commercial and collective catering, local shops, and large and medium-sized retail surfaces. It operates in the food wholesale supply chain rather than as a consumer-facing technology platform.
Organisations in wholesale fresh produce typically sit between growers, logistics partners, and professional buyers. A listing that names such a firm matters because supply-chain businesses often hold commercial contact details, order and delivery records, invoicing information, and internal operational data that third parties might misuse if those records were ever obtained. That is a sector-level observation about what such firms commonly process—not a statement that any particular dataset from Rosello et Fils was taken or published.
The information in question
The facts available for this article state that data types named as exposed are not disclosed. People affected are listed as unknown. Therefore it is not possible—and not appropriate—to assert that specific categories of personal or commercial data were stolen, leaked, or posted. The listing’s own wording, if any exists beyond the name of the organisation, remains the attacker’s claim and marketing, not a verified inventory.
If files from a fruit and vegetable wholesaler of this type were ever copied, firms in the sector typically hold information such as business contact details for buyers and suppliers, delivery addresses, order histories, payment and invoicing records, and internal staff or contractor details needed to run logistics. Some may also hold limited personal data tied to accounts payable, transport, or site access. None of that should be read as confirmation that Eclipse obtained or released those materials from Rosello et Fils. Exact contents in this case are unconfirmed.
Why it matters
Unverified leak-site listings still create real-world uncertainty. Customers, suppliers, and staff may wonder whether emails, phone numbers, or commercial terms could surface later. If data were involved, risks could include targeted phishing that references genuine trading relationships, invoice fraud aimed at accounts payable, or social engineering against logistics partners. For the organisation, even an unconfirmed claim can consume attention, raise questions from counterparties, and require careful internal checks—without any public proof that systems were compromised.
It also matters because food wholesale sits in a chain that many communities depend on. Disruption or distrust in professional catering and retail supply can have knock-on effects that go beyond a single company name on a criminal site. At the same time, overstating an unproven claim can itself harm reputation and spread false certainty. The balanced position is conditional: if personal or business information related to this firm ever appears in criminal channels, the usual fraud and privacy harms apply; if the listing is empty theatre, those harms may never materialise. Public detail does not yet settle which is true.
What to do now
Because the incident is unconfirmed and data types are undisclosed, advice stays precautionary. People and businesses that deal with Rosello et Fils—or believe they might—can take measured steps without assuming their information is already exposed.
- Treat unexpected emails, calls, or payment-change requests that mention the company or regional produce supply as higher risk; verify through known channels before acting.
- If you are a commercial counterparty, confirm bank details and order instructions out-of-band and watch for invoice fraud patterns.
- Monitor relevant accounts for unusual login or reset activity; use unique passwords and multi-factor authentication where available.
- Staff and partners who handle logistics or finance should be alert to spear-phishing that references real routes, depots, or buyer names.
- Follow only official statements from the company or competent authorities if and when they appear; do not rely on criminal leak sites for status.
- Readers can run a free exposure scan of their email to check whether their address has already appeared in other known breach datasets unrelated to this claim.
Eclipse’s listing of Rosello et Fils on or about September 14, 2026, is a claim on a ransomware leak site. The company has not publicly confirmed the claim as of writing. Scale, method, and data contents remain undisclosed in the facts at hand. Conditional vigilance is warranted; treating the accusation as proven fact is not.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
More recent breaches
Dublin City Schools GA Listed by Eclipse Ransomware GroupTTG Asia Media Listed by Eclipse Ransomware GroupThe Zhou Law Group Listed by Eclipse Ransomware GroupRoyal Plaza On Scotts Listed by Eclipse Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Rosello et Fils Listed by Eclipse Ransomware Group →
Publicly posted by eclipse — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.