BreachCensus

medusa

First seen January 11, 2023Active518 claimed victims

The claims below are reproduced as posted by medusa on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
RAYAB Consulting EngineersFebruary 22, 2023ransomware_live
International Center of PhotographyFebruary 19, 2023ransomware_live
AP Emissions TechnologiesFebruary 17, 2023ransomware_live
Foamtec InternationalFebruary 16, 2023ransomware_live
PetroChina IndonesiaFebruary 15, 2023ransomware_live
Eureka Casino ResortFebruary 13, 2023ransomware_live
Tonga CommunicationsFebruary 11, 2023ransomware_live
Diethelm Keller Aviation Pte LtdFebruary 9, 2023ransomware_live
EnComFebruary 3, 2023ransomware_live
PFA SystemsFebruary 3, 2023ransomware_live
Elim ClinicFebruary 3, 2023ransomware_live
Elektro RichterFebruary 3, 2023ransomware_live
European WindowFebruary 2, 2023ransomware_live
Bank of AfricaJanuary 30, 2023ransomware_live
EightPixelsSquareJanuary 25, 2023ransomware_live
AglobisJanuary 20, 2023ransomware_live
Integerity TaxJanuary 11, 2023ransomware_live
Grace Church InternationalJanuary 11, 2023ransomware_live
← NewerPage 6 of 6

Claim data from ransomware.live and RansomLook (CC BY 4.0).