LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › Savills France Listed by qilin Ransomware Group

HIGH severityUnverified claimHow we verify

Savills France Listed by qilin Ransomware Group: What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 27, 2026
Savills France Listed by qilin Ransomware Group

Reported July 27, 2026.

HIGH
Severity
1
Data types exposed
July 27, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Savills France has been listed by the Qilin ransomware group following the exfiltration of internal files, with the incident made public on July 27, 2026. Individuals connected to the company are advised to monitor their accounts and consider enhanced security measures.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Was your email in the Savills France Listed by qilin Ransomware Group breach?
See every leak tied to your email — not just this one. 15-second check, no card, no account.

People who have dealt with Savills France — clients, tenants, employees, or business partners — may be wondering whether their personal or commercial information was caught up in a claimed ransomware incident. Public detail is limited: the firm was listed on a ransomware group’s leak site, and the group asserts that it took internal files. How many people are affected, and exactly what was taken, has not been confirmed in the available record.

That uncertainty is itself the practical stake. Until more is known, anyone with a past or present connection to the organisation has reason to treat the claim seriously, watch for unusual contact, and take basic steps to protect accounts and documents tied to property, employment, or transactions handled through Savills France.

Breaking down the breach

According to the reported record, Savills France was listed on the qilin ransomware leak site on or around 27 July 2026. The group claims to have stolen internal data in a ransomware attack and to have exfiltrated internal files. The number of people affected is unknown. No further public detail has been given in the available facts about how the intrusion occurred, how long any access lasted, whether systems were encrypted, or whether any ransom demand was made or paid.

What is established in the record is therefore narrow: a leak-site listing and a claim of internal-file theft. Everything else — scale, method, confirmation by the organisation, and the precise contents of any taken material — remains undisclosed or unconfirmed at the time of the report.

Inside qilin

Qilin is a known ransomware operation that has appeared repeatedly in public reporting on double-extortion attacks. Groups of this type typically gain access to a network, move laterally, exfiltrate data, and then threaten to publish or sell that data if a payment is not made. Many such actors operate on a ransomware-as-a-service model, in which affiliates carry out intrusions using shared tools and infrastructure while the core group handles negotiation and leak-site publication.

Public descriptions of qilin’s activity have often included pressure tactics such as timed leak-site posts and staged releases of sample files. Those patterns are general to the actor’s documented behaviour and are not specific claims about Savills France beyond what the facts state. In this case, the only attribution in the record is the listing itself and the group’s claim that internal data was stolen. That listing should be treated as an unverified claim unless and until it is independently confirmed.

Who is Savills France?

Savills France is the French arm of Savills, an international real-estate services firm. Organisations of this kind advise on commercial and residential property, manage assets and transactions, and handle leasing, valuation, and related professional services. They routinely hold records that touch clients, landlords, tenants, employees, and counterparties — including identity and contact details, contract and transaction files, and internal business documents.

A breach affecting such a firm is consequential because property and professional-services work concentrates sensitive commercial and personal information in one place. Even when the exact scope of an incident is unknown, the sector’s typical data holdings mean that clients and staff can face follow-on risks if internal files are copied and later misused.

The information in question

The available facts name the exposed material only as internal files exfiltrated in a ransomware attack. No inventory of specific data types — such as names, financial records, identity documents, or client files — has been disclosed in the record. The group claims to have stolen internal data; the precise contents remain unconfirmed.

Firms in real-estate services typically hold client and counterparty contact information, transaction and lease documentation, employee records, and internal correspondence and operational files. That is the kind of material that could, in principle, be present in “internal files.” It is not established fact that any particular category was taken in this incident. Readers should treat the exposure as claimed and incomplete until official confirmation or a fuller disclosure appears.

What's at stake

For individuals, the main risks are practical rather than abstract. If internal files included personal or commercial details, those details could be used for targeted phishing, impersonation, or social-engineering attempts that reference real property deals, tenancies, or employment. Business partners could face similar pressure if contract or negotiation material was among what the group claims to hold.

For the organisation, a claimed exfiltration raises operational, legal, and trust issues: the need to investigate, to notify regulators and affected parties where required, and to contain any ongoing access. Public detail on those steps is not part of the current record.

Concrete points to keep in view:

What to do if you're exposed

If you have reason to believe your information may have been held by Savills France, start with basics. Monitor bank, email, and property-related accounts for unexpected messages or changes. Treat unsolicited requests that reference real deals, leases, or HR matters with extra caution; verify through a known channel before responding or opening attachments. Consider placing fraud alerts or credit monitoring where that is available in your country, and update passwords on important accounts, preferably with a password manager and multi-factor authentication.

Keep records of any suspicious contact. If you are an employee or client, watch for official notices from the firm rather than relying solely on third-party claims. You can also run a free exposure scan of your email to check whether your address has already appeared in known breach data sets — a simple way to see whether your details have surfaced elsewhere and to decide what to secure next.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySavills France security record
100/100
DoxxScan™ · Low doxx risk
A+ 100Safest — no known major breach

0 reported incidents on record.

See Savills France’s full breach history →

More recent breaches

Contacto Garantido Listed by qilin Ransomware GroupJuly 26, 2026Jubilee Jobs Listed by qilin Ransomware GroupJuly 25, 2026The Myers Y Cooper Listed by qilin Ransomware GroupJuly 25, 2026ABM Enviro Listed by qilin Ransomware GroupJuly 23, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Savills France Listed by qilin Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by qilin — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram