SAD'S Interim
rhysidaThis record tracks a ransomware attack claimed by the rhysida group against SAD'S Interim. It collects the publicly disclosed attack details — sector, location and timeline — as published on the operator's leak site and indexed by Breach House.
Window Zero
EXPOSURE GAPWindow Zero is the time the breach stayed in the open before anyone said so — the gap between when the attack was first discovered on the operator's leak site (t1) and when it was publicly disclosed (t2). The wider this window, the longer victims, staff and customers were exposed with no warning.
Attack Summary
SAD'S Interim Since 2000, SAD'S INTERIM has established itself as a key player in the temporary employment sector.Bank statements (relev�s) with SEPA credit transfersFactoring: invoice import batches, client receivables ledgers (encours) with EUR amounts and named clients, payment receipts (quittances)SQL backups of the BRANIPP ERP (the temp-workers payroll database)Payslips (bulletins de salaire) and payroll validation workbooksPermanent-staff employment contracts signed by the owners (Sadoun family)Temp-worker contracts, Pole Emploi attestationsPassports (EU and third-country nationals)CARTE BTP (construction-worker cards with photo and DOB)carte Vitale (health-insurance cards)RIB (bank account details)NIR (national insurance numbers)MDPH (disability recognition documents) More
Leak Screenshots
3 CAPTUREDCaptured directly from the operator's leak site by our collector, last checked 2026-09-10. Verdict evidence: [H6] All files was uploaded to public access, data hunters, enjoy
Proof files published by the operator — 2 image(s) harvested from this entry. Content is locked; type and dimensions shown.
Capture history — 3 day(s) tracked. Content is locked.