RANSOMWARE VICTIMDUPLICATE CLAIM

Valgo SA

INCRANSOM📍 France (FR)📅 February 19, 2026
8
same group

Attack Intelligence

Valgo SA was compromised in a ransomware attack attributed to INCRANSOM in February 2026. The organization, operating in an undisclosed sector in France, was added to the group's data leak site as part of an extortion campaign.

INCRANSOM operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

VALGO SAS 72 Rue Aristide Briand, 76650 Petit-Couronne, France valgo.com VALGO is a French company that specializes in environmental services, particularly in the areas of asbestos removal, soil decontamination, and the revitalization of polluted industrial sites. Established in 2004, VALGO has developed a strong reputation for its expertise in managing contaminated sites and providing innovative solutions for environmental remediation. VALGO operates a national network of 17 branches and has an international presence, allowing it to address diverse environmental challenges across different regions. Total data in the leak: 279 GB (225,372 Files, 50,902 Folders) Leaked data: - Clients: Renault Group, Sectra,Evarisk, EPF Reunion,Rousselet and many others famous companies - Data Classification: confidential, Private/Proprietary - Special data: Complete information on projects in countries of operation: contracts, NDAs, correspondence with clients, information about manufacturers of the equipment used and the chemical elements employed, labaratory reserch, hazard information, corporate information, and much more. - Financial data: invoicing and payment records, financial planning documents, accounting, and customer information and VERY IMPORTANT information!

Additional Details

Other Victims — INCRANSOM (8)

Quick Facts

CountryFrance (FR)
Attack DateFeb 19, 2026
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

INCRANSOM
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.