Ransomware Group intelligence
Medusa
InactiveTrack Medusa with 521 published victims and 12 known leak locations in a single intelligence view.
Overview
Medusa is tracked by Breach House as a ransomware group with 521 published victims.
United States is currently the most targeted country in this dataset.
12 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (12)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 10 | Onion service | Down checked 2h ago | hupxs7ps7md24kpz4lwsbra64abgxjx3pcc2wuca5ibawf2g5hlpfyqd.onion |
| Leak location 8 | Onion service | Down checked 2h ago | cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion |
| Leak location 6 | Onion service | Down checked 2h ago | s7lmmhlt3iwnwirxvgjidl6omcblvw2rg75txjfduy73kx5brlmiulad.onion |
| Leak location 12 | Onion service | Down checked 2h ago | 7aqabivkwmpvjkyefonf3gpy5gsubopqni7kcirsrq3pflckxq5zz4id.onion |
| Leak location 11 | Onion service | Down checked 2h ago | 62foekhv5humjrfwjdyd2dgextpbf5i7obguhwvfoghmu3nxpkmxlcid.onion |
| Leak location 4 | Onion service | Down checked 2h ago | dlmfciajg5s4vliyo5dhs5jyzhi2xr2fnkebul46lpf4xudtqiue4nid.onion |
| Leak location 7 | Web location | Down checked 2h ago | 45.9.148.39 |
| Leak location 5 | Onion service | Down checked 2h ago | kyfiw76eol6ph2mq7pi5e5tdvce37bicddhai62qhdc5ja6jdchz4qqd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion |
| Leak location 9 | Onion service | Down checked 2h ago | xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion |
| Leak location 2 | Onion service | Down checked 2h ago | medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion |
| Leak location 1 | Onion service | Down checked 2h ago | medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion |
Top Activity Sectors (17)
- Communication / Marketing 105
- Services 55
- Public Sector 54
- Healthcare / Pharma 52
- Education 40
- Finance / Legal / Insurance 32
- Construction / Real Estate 31
- IT 30
- Manufacturing / Engineering 28
- Retail / E-commerce 20
- Hospitality / Food & Beverage / Tourism 17
- Energy 13
- Transportation / Travel / Logistics 13
- Agriculture / Food 9
- NGOs / Associations 7
- Telecommunications 6
- Not identified 4
Typical Attacks (64)
▼How Medusa typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Medusa Group, Medusa Ransomware.
-
T1583.006 Web Services Resource Development
What they do: Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions.
What that means: Adversaries may register for web services that can be used during targeting.
-
T1585.001 Social Media Accounts Resource Development
What they do: Medusa Group has created social media accounts including Telegram and X to publicize their activities.
What that means: Adversaries may create and cultivate social media accounts that can be used during targeting.
-
T1585.002 Email Accounts Resource Development
What they do: Medusa Group has created email accounts used in ransomware negotiations.
What that means: Adversaries may create email accounts that can be used during targeting.
-
T1588.002 Tool Resource Development
What they do: Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
T1608.002 Upload Tool Resource Development
What they do: Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise.
What that means: Adversaries may upload tools to third-party or adversary controlled infrastructure to make it accessible during targeting.
-
T1650 Acquire Access Resource Development
What they do: Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs).
What that means: Adversaries may purchase or otherwise acquire an existing access to a target system or network.
-
What they do: Medusa Group has utilized compromised legitimate local and domain accounts within the victim environment to facilitate remote access and lateral movement sometimes in combination with PsExec.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Medusa Group has leveraged public facing vulnerabilities in their campaigns against victim organizations to gain initial access.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1047 Windows Management Instrumentation Execution
What they do: Medusa Group has utilized Windows Management Instrumentation to query system information.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: Medusa Group has leveraged PowerShell for execution and defense evasion.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Medusa Group has used Windows Command Prompt to control and execute commands on the system to include ingress, network, and filesystem enumeration activities.
What that means: Adversaries may abuse the Windows command shell for execution.
-
What they do: Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy.
What that means: Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network.
-
T1106 Native API Execution
What they do: Medusa Group has leveraged Windows Native API functions to execute payloads.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1559 Inter-Process Communication Execution
What they do: Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication.
What that means: Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution.
-
T1559.001 Component Object Model Execution
What they do: Medusa Group has leveraged Component Object Model (COM) to bypass UAC.
What that means: Adversaries may use the Windows Component Object Model (COM) for local code execution.
-
T1569.002 Service Execution Execution
What they do: Medusa Group has utilized PsExec to execute scripts and commands within victim environments.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Medusa Group has modified Registry keys to elevate privileges, maintain persistence and allow remote access.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1136.002 Domain Account Persistence
What they do: Medusa Group has created a domain account within the victim environment.
What that means: Adversaries may create a domain account to maintain access to victim systems.
-
T1505.003 Web Shell Persistence
What they do: Medusa Group has utilized webshells to an exploited Microsoft Exchange Server.
What that means: Adversaries may backdoor web servers with web shells to establish persistent access to systems.
-
What they do: Medusa Group has used vulnerable or signed drivers to modify security solutions on victim devices.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027.002 Software Packing Stealth
What they do: Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1027.010 Command Obfuscation Stealth
What they do: Medusa Group has obfuscated PowerShell scripts with Base64 encoding.
What that means: Adversaries may obfuscate content during command execution to impede detection.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Medusa Ransomware has utilized XOR encrypted strings.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.003 Clear Command History Stealth
What they do: Medusa Group has cleared command history by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.
What that means: In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.
-
T1070.004 File Deletion Stealth
What they do: Medusa Group has deleted previously installed tools.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1218.014 MMC Stealth
What they do: Medusa Group has leveraged Microsoft Management Console (MMC) to facilitate lateral movement and to interact locally or remotely with victim devices using the command `mmc.exe compmgmt.msc /computer:{hostname/ip}`.
What that means: Adversaries may abuse mmc.exe to proxy execution of malicious .msc files.
-
T1564.003 Hidden Window Stealth
What they do: Medusa Group has utilized the `ShowWindow` API function to hide the current window.
What that means: Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
-
T1679 Selective Exclusion Stealth
What they do: Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device.
What that means: Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution.
-
T1553.002 Code Signing Defense Impairment
What they do: Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools.
What that means: Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1686 Disable or Modify System Firewall Defense Impairment
What they do: Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings.
What that means: Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action.
-
T1690 Prevent Command History Logging Defense Impairment
What they do: Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.
What that means: Adversaries may impair command history logging to hide commands they run on a compromised system.
-
T1003.001 LSASS Memory Credential Access
What they do: Medusa Group has leveraged Mimikatz to dump LSASS to harvest credentials.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1003.003 NTDS Credential Access
What they do: Medusa Group has accessed the ntds.dit file to engage in credential dumping.
What that means: Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights.
-
T1007 System Service Discovery Discovery
What they do: Medusa Ransomware has leveraged an encoded list of services that it designates for termination.
What that means: Adversaries may try to gather information about registered local system services.
-
T1016 System Network Configuration Discovery Discovery
What they do: Medusa Group has obtained host network details utilizing the command `cmd.exe /c ipconfig /all`.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Medusa Group has used PDQ Inventory to get an inventory of the endpoints on the network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1033 System Owner/User Discovery Discovery
What they do: Medusa Group has utilized PsExec to execute `quser` to discover the user session information.
What that means: Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
-
T1046 Network Service Discovery Discovery
What they do: Medusa Group has the capability to use living off the land (LOTL) binaries to perform network enumeration.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1057 Process Discovery Discovery
What they do: Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1069.002 Domain Groups Discovery
What they do: Medusa Group has utilized the `net group` command to query domain groups within the victim environment.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: Medusa Group has leveraged `cmd.exe` to identify system info `cmd.exe /c systeminfo`.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Medusa Group has searched for files within the victim environment for encryption and exfiltration.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.001 Local Account Discovery
What they do: Medusa Group has leveraged `net user` for account discovery.
What that means: Adversaries may attempt to get a listing of local system accounts.
-
T1124 System Time Discovery Discovery
What they do: Medusa Ransomware has discovered device uptime through `GetTickCount()`.
What that means: An adversary may gather the system time and/or time zone settings from a local or remote system.
-
T1135 Network Share Discovery Discovery
What they do: Medusa Group has identified network shares using `cmd.exe /c net share`.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1518.001 Security Software Discovery Discovery
What they do: Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1652 Device Driver Discovery Discovery
What they do: Medusa Group has queried drivers on the victim device through the command `driverquery`.
What that means: Adversaries may attempt to enumerate local device drivers on a victim host.
-
T1680 Local Storage Discovery Discovery
What they do: Medusa Ransomware has enumerated logical drives on infected hosts.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: Medusa Group has used RDP to conduct lateral movement and exfiltrate data.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1071.001 Web Protocols Command and Control
What they do: Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS).
What that means: Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
-
T1090.003 Multi-hop Proxy Command and Control
What they do: Medusa Group has used TOR nodes for communications.
What that means: Adversaries may chain together multiple proxies to disguise the source of malicious traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1219 Remote Access Tools Command and Control
What they do: Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1573.002 Asymmetric Cryptography Command and Control
What they do: Medusa Group has used HTTPS for command and control.
What that means: Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1529 System Shutdown/Reboot Impact
What they do: Medusa Group has manually turned off and encrypted virtual machines.
What that means: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
-
T1657 Financial Theft Impact
What they do: Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (27)
▼Software Medusa has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
!!!READ_ME_MEDUSA!!!.txt
$$\ $$\ $$$$$$$$\ $$$$$$$\ $$\ $$\ $$$$$$\ $$$$$$\ $$$\ $$$ |$$ _____|$$ __$$\ $$ | $$ |$$ __$$\ $$ __$$\ $$$$\ $$$$ |$$ | $$ | $$ |$$ | $$ |$$ / \__|$$ / $$ | $$\$$\$$ $$ |$$$$$\ $$ | $$ |$$ | $$ |\$$$$$$\ $$$$$$$$ | $$ \$$$ $$ |$$ __| $$ | $$ |$$ | $$ | \____$$\ $$ __$$ | $$ |\$ /$$ |$$ | $$ | $$ |$$ | $$ |$$\ $$ |$$ | $$ | $$ | \_/ $$ |$$$$$$$$\ $$$$$$$ |\$$$$$$ |\$$$$$$ |$$ | $$ | \__| \__|\________|\_______/ \______/ \______/ \__| \__| -----------------------------[ Hello, [snip] !!! ]-------------------------- WHAT HAPPEND? ------------------------------------------------------------ 1. We have PENETRATE your network and COPIED data. * We have penetrated entire network including backup system and researched all about your data. * And we have extracted all of your networks including sub offices and your service clients networks valuable data and copied them to private cloud storage. 2. We have ENCRYPTED some your files. While you are reading this message, it means you found your files and data has been ENCRYPTED by world's strongest ransomware. We have access to all of your sub offices and client service networks but didn't lock them all for your brand and privacy. We can solve this issue sliently and smoothly without 3rd parties and we decided lock only some of your main network only. But don't worry, we can restore everything to the original without harming your business. There is only one possible way to get back your systems and business - CONTACT us via LIVE CHAT and pay for the special MEDUSA DECRYPTOR and DECRYPTION KEYs, Data deletion, Keep silent in media. This MEDUSA DECRYPTOR will restore your entire network, This will take less than 1 business day. WHAT GUARANTEES? --------------------------------------------------------------- We can post your data to the public and send emails to your customers. We have professional OSINTs and media team for leak data to telegram, facebook, twitter channels and top news websites. Have a look about us on twitter. You can suffer significant problems due disastrous consequences, leading to loss of valuable intellectual property and other sensitive information, costly incident response efforts, information misuse/abuse, loss of customer trust, brand and reputational damage, legal and regulatory issues. After paying for the data breach and decryption, we guarantee that your data will never be leaked and this is also for our reputation. YOU should be AWARE! --------------------------------------------------------------- If you're not in main chile office, inform your supervisors and stay calm! We will speak only with an authorized person. It can be the CEO, top management, etc. In case you are not such a person - DON'T CONTACT US! Your decisions and action can result in serious harm to your company! If you do not contact us within 3 days, We will start publish your case to our official blog and everybody will start notice your incident! If you do not contact us within 5 days, We will start publish your case and leak video on all social channels and send emails to your customers! --------------------[ Official blog tor address ]-------------------- Using TOR Browser(https://www.torproject.org/download/): http://medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion/ CONTACT US! ----------------------[ Your company live chat address ]--------------------------- Using TOR Browser(https://www.torproject.org/download/): http://medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion/[snip] Or Use Tox Chat Program(https://qtox.github.io/) Add user with our tox ID and wait 24h : 4AE245548F2A225882951FB14E9BF87EE01A0C10AE159B99D1EA62620D91A372205227254A9F Our support email: ( [email protected] ) Company identification hash: [snip]
!!!READ_ME_MEDUSA!!!_2.txt
$$\ $$\ $$$$$$$$\ $$$$$$$\ $$\ $$\ $$$$$$\ $$$$$$\ $$$\ $$$ |$$ _____|$$ __$$\ $$ | $$ |$$ __$$\ $$ __$$\ $$$$\ $$$$ |$$ | $$ | $$ |$$ | $$ |$$ / \__|$$ / $$ | $$\$$\$$ $$ |$$$$$\ $$ | $$ |$$ | $$ |\$$$$$$\ $$$$$$$$ | $$ \$$$ $$ |$$ __| $$ | $$ |$$ | $$ | \____$$\ $$ __$$ | $$ |\$ /$$ |$$ | $$ | $$ |$$ | $$ |$$\ $$ |$$ | $$ | $$ | \_/ $$ |$$$$$$$$\ $$$$$$$ |\$$$$$$ |\$$$$$$ |$$ | $$ | \__| \__|\________|\_______/ \______/ \______/ \__| \__| -----------------------------[ Hello, [snip] !!! ]-------------------------- Sorry to interrupt your busy business. WHAT HAPPEND? ------------------------------------------------------------ 1. We have PENETRATE your network and COPIED data. We have penetrated your entire network and researched all about your data. And we have copied all of your confidential data and uploaded to private storage. * You're running a highly valued business and your data was very crucial. 2. We have ENCRYPTED your files. While you are reading this message, it means your files and data has been ENCRYPTED by world's strongest ransomware. Your files have encrypted with new military-grade encryption algorithm and you can not decrypt your files. But don't worry, we can decrypt your files. There is only one possible way to get back your computers and servers, keep your privacy safe - CONTACT us via LIVE CHAT and pay for the special MEDUSA DECRYPTOR and DECRYPTION KEYs. This MEDUSA DECRYPTOR will restore your entire network within less than 1 business day. WHAT GUARANTEES? --------------------------------------------------------------- We can post all of your critial data to the public and send emails to your competitors. We have professional OSINTs and media team for leak data to telegram, facebook, twitter channels and top news websites. You can easily search about us. You can suffer significant problems due to disastrous consequences, leading to loss of valuable intellectual property and other sensitive information, costly incident response efforts, information misuse/abuse, loss of customer trust, brand and reputational damage, and legal and regulatory issues. After paying for the data breach and decryption, we guarantee that your data will never be leaked and make everything silent, this is also for our reputation. YOU should be AWARE! --------------------------------------------------------------- We will speak only with an authorized person. It can be the CEO, top management etc. In case you ar not such a person - DON'T CONTACT US! Your decisions and action can result in serious harm to your company! Inform your supervisors and stay calm! If you do not contact us within 48 hours, We will start publish your case to our official blog and everybody will start notice your incident! --------------------[ Telegram channel ]-------------------- https://t.me/+yXOcSjVjI9tjM2E0 --------------------[ Official blog tor address ]-------------------- Using TOR Browser(https://www.torproject.org/download/): http://xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion/ http://cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion/ CONTACT US! ----------------------[ Your company live chat address ]--------------------------- Using TOR Browser(https://www.torproject.org/download/): http://uyku4o2yg34ekvjtszg6gu7cvjzm6hyszhtu7c55iyuzhpr4k5knewyd.onion/[snip] Backup Mirrors: http://5ar4vuckm3k7osdlzskqkaqmqr4jjpmdikuotmlpkrbsxx7ard3xetyd.onion/[snip] --------------------[ Or Use Tox Chat Program(https://utox.org/uTox_win64.exe) ]-------------------- Add user with our tox ID : 061AA6BDE8F6DE6C92F0D6E077359BF6911FCAF80030E82B3A3DB65E63C8011343D34F956FEC Our support email: ( [email protected] ) Company identification hash: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (521)
Search, filter and paginate the victim timeline for Medusa. Showing 101–200 of 521.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Portland Street Honda id18407 View details | Canada | Communication / Marketing | ||
|
Portland Street Honda (founded in 1992) is dealership for all of your Honda needs and products. Portland Street Honda corporate office is located in 36 Baker Dr Ste 200, Dartmouth, Nova Scotia, B2W 6K1, Canada and has 68 employees. |
|||||
| Ransomware | Karen S Pouliot id18406 View details | Services | |||
|
Karen S Pouliot, CPA is to provide accounting, tax and management services to clients. Karen S Pouliot, CPA corporate office is located in 147 Old Solomons Island Road, Suite 208 Annapolis, Maryland 21401. The total amount of data leakage is 101.20 GB |
|||||
| Ransomware | Customer Management Systems id18290 View details | United States | Services | ||
|
Customer Management Systems (founded in 2003) introduced a state of the art professional call center with customer focused processes and the capability to serve both product and service providers cost effectively. Customer Management Systems corporate office is located in 1616 W Airport Blvd, Sanford, Florida, 32773, United States and has 127 employees. The total amount of data leakage is 117.91 GB |
|||||
| Ransomware | CPI Books id18289 View details | United Kingdom | Communication / Marketing | ||
|
CPI Books is the UK’s book printing service provider. CPI produces books and journals across multiple channels including; Trade, STMA, Tax, Law, Bibles, Catalogues, as well as Self-Publishing. Cpi Uk corporate office is located in Copland Way, Beccles, Norfolk, NR34 7TL, United Kingdom and has 2,500 employees. The total amount of data leakage is 183.20 |
|||||
| Ransomware | Bell Ambulance id18117 View details | United States | Healthcare / Pharma | ||
|
Bell Ambulance company provides emergency transportation services for patients to medical institutions, working around the clock and having everything necessary to ensure transportation in any condition and with any illness. Bell Ambulance corporate office is located in 549 E Wilson St, Milwaukee, Wisconsin, 53207, United States and has 500 employees. The total amount of data leakage is 219.50 GB |
|||||
| Ransomware | Kable Product Services id18110 View details | United States | Communication / Marketing | ||
|
Kable Product Services Inc. is a transportation, logistics, supply chain and storage company. Kable Product Services corporate office is located in 4275 Thunderbird Ln, Fairfield, Ohio, 45014, United States and has 115 employees. |
|||||
| Ransomware | City of Aurora id18109 View details | United States | Public Sector | ||
|
Aurora is a home rule city located in Arapahoe, Adams, and Douglas counties, Colorado, United States. The city's population was 386,261 at the 2020 United States census with 336,035 residing in Arapahoe County, 47,720 residing in Adams County, and 2,506 residing in Douglas County. City of Aurora corporate office is located in 15151 E Alameda Pkwy Ste 4600, Aurora, Colorado, 80012, United States |
|||||
| Ransomware | Aurora Boardworks id17798 View details | United States | Agriculture / Food | ||
|
Aurora Boardworks manufactures custom built circuit assemblies for industrial, medical, military, agriculture, oil and gas applications. Aurora Boardworks corporate office is located in 103 Grant St, Aurora, Nebraska, 68818, United States and has 24 employees. |
|||||
| Ransomware | Heartland Health Center id17797 View details | United States | Healthcare / Pharma | ||
|
Heartland Health Center - provides services in the healthcare cloud, namely, medical, stomotological, treatment of mental health and cognitive -behavioral therapy. Heartland Health Center corporate office is located in 3307 W Capital Ave, Grand Island, Nebraska, 68803, United States and has 31 employees. |
|||||
| Ransomware | Laurens School District 56 id17796 View details | United States | Education | ||
|
Laurens School District 56 is a school district in South Carolina (Laurens County) which has about 2,800 students. Laurens County School District 56 corporate office is located in 211 N Broad St, Clinton, South Carolina, 29325, United States and has 118 employees. The total amount of data leakage is 2.40 TB |
|||||
| Ransomware | Mundelein Park & Recreation District id17795 View details | United States | Communication / Marketing | ||
|
Mundelein Park & Recreation District (founded in 1954) provides 33 park sites offering over 735 acres of open space, playgrounds, ball fields, lakes, and trails. Mundelein Park & Recreation District corporate office is located in 1401 N Midlothian Rd, Mundelein, Illinois, 60060, United States and has 437 employees. The total amount of data leakage is 118.20 GB |
|||||
| Ransomware | Friendship House id17794 View details | United States | Healthcare / Pharma | ||
|
Friendship House - clinic provides outpatient and inpatient services for the treatment of mental health and substance abuse. Friendship House corporate office is located in 406 W Koenig St, Grand Island, Nebraska, 68801, United States and has 9 employees. |
|||||
| Ransomware | Metropolitan Borough of Gateshead id17715 View details | United Kingdom | Public Sector | ||
|
The Metropolitan Borough of Gateshead is a metropolitan borough in the metropolitan county of Tyne and Wear, England. It includes Gateshead, Rowlands Gill, Whickham, Blaydon, Ryton, Felling, Birtley, Pelaw, Dunston and Low Fell. The borough forms part of the Tyneside conurbation, centred on Newcastle upon Tyne. At the 2021 census, the borough had a population of 196154. Gateshead Council office is located in 12 Gladstone Ter, Gateshead, Tyne and Wear, NE8 4DY, United Kingdom and has 684 employees. |
|||||
| Ransomware | Martin Energy Group Services id17714 View details | United States | Energy | ||
|
Martin Energy Group Services are a complete solutions provider for generator packages, combined heat and power (CHP) systems, microgrids, and anaerobic digester design & construction. Martin Energy Group Services corporate office is located in 39415 Excelsior Dr, Latham, Missouri, 65050, United States and has 120 employees. The total amount of data leakage is 320.90 GB |
|||||
| Ransomware | G&S Electric LLC id17713 View details | United States | Public Sector | ||
|
G&S Electric LLC is a trusted electrical contractor serving Shreveport, Benton, and Bossier City, LA, specializing in both commercial and residential projects. G&S Electric corporate office is located in 2127 Mcclellan St, Shreveport, Louisiana, 71103, United States and has 23 employees. |
|||||
| Ransomware | Benton Police Department id17712 View details | United States | Public Sector | ||
|
Benton Police Department - city police department. Benton Police Department corporate office is located in 114 S East St Ste 100, Benton, Arkansas, 72015, United States and has 52 employees. |
|||||
| Ransomware | Robinson Family Dentistry id17657 View details | United States | Healthcare / Pharma | ||
|
Robinson Family Dentistry - family dental clinic. Robinson Family Dentistry corporate office is located in 1281 Yeamans Hall Road, Hanahan, SC 29410, US. |
|||||
| Ransomware | Crager LaBorde id17656 View details | United States | Services | ||
|
Crager LaBorde company provides services small to medium sized businesses reach their potential and goals with services that include income taxes past and present, monthly write-up, live payrolls, LLC and corporation setup, business consulting and quarterly sales and payroll taxes. Crager LaBorde corporate office is located in 335 Southfield Rd Ste 200, Shreveport, Louisiana, 71105, United States and has 17 employees. |
|||||
| Ransomware | HCRG Care Group id17655 View details | United Kingdom | Healthcare / Pharma | ||
|
HCRG Care Group (founded in 2006) is a healthcare company that provides healthcare services such as physician clinics and specialty clinics. HCRG Care corporate office is located in The Heath Business and Technical Park, Runcorn, Cheshire, WA7 4QX, United Kingdom and has 5,000 employees. The total amount of data leakage is 2.275 Tb Direct file tree download link due to big file size: https://www.sendspace.com/file/8i7cca |
|||||
| Ransomware | Cache Valley ENT id17500 View details | United States | Healthcare / Pharma | ||
|
Cache Valley ENT is a local ear, nose, and throat (ENT) clinic located in North Logan, UT. Cache Valley ENT corporate office is located in 2380 N 400 E Ste D, Logan, Utah, 84341, United States and has 18 employees. The total amount of data leakage is 210.10 GB |
|||||
| Ransomware | JP Express id17499 View details | United States | Communication / Marketing | ||
|
JP Express - large transport company providing cargo transportation. JP Express corporate office is located in PO Box 819, Deer Park, New York, 11729, United States and has 260 employees. The total amount of data leakage is 97.40 GB |
|||||
| Ransomware | Central District Health Department id17498 View details | United States | Public Sector | ||
|
Central District Health Department is a company that operates in the Government industry in the field of health care. Central District Health Department corporate office is located in 1137 S Locust St, Grand Island, Nebraska, 68801, United States and has 119 employees. The total amount of data leakage is 84.40 GB |
|||||
| Ransomware | Natures Organics id17436 View details | Australia | Agriculture / Food | ||
|
Natures Organics manufacturer of sustainable and eco-friendly food and personal care products. Natures Organics corporate office is located in 31 Cornhill St, Ferntree Gully, Victoria, 3156, Australia and has 88 employees. The total amount of data leakage is 142.85 |
|||||
| Ransomware | Paignton Zoo id17435 View details | United Kingdom | NGOs / Associations | ||
|
Paignton Zoo - large zoo, as well as a conservation and charitable organization. Paignton Zoo corporate office is located in Zoo Totnes Rd, Paignton Torquay, Devon, TQ4 7EU, United Kingdom and has 86 employees. The total amount of data leakage is 271.60 GB |
|||||
| Ransomware | SRP Companies id17434 View details | United States | Retail / E-commerce | ||
|
SRP Companies is North American provider of consumer products and single-source retail solutions to retail outlets spanning the convenience store, truck & travel, theme parks & resorts, sporting good and travel channels. With seven distribution centers, the company provides route-based direct-store-delivery (DSD) services and specializes in product innovation, supply chain optimization and data analytics. SRP Companies corporate office is located in 85 Rio Grande Dr Ste 200, Castle Rock, Colorado, 80104, United States and has 1,000 employees. The total amount of data leakage is 1.35 TB |
|||||
| Ransomware | Braum's id17433 View details | United States | Agriculture / Food | ||
|
Braum's (founded in 1968) is a family-owned fast-food restaurant chain and dairy shop. Braum's corporate office is located in PO Box 25429, Oklahoma City, Oklahoma, 73125, United States and has 6,500 employees. The total amount of data leakage is 612.50 GB |
|||||
| Ransomware | Grail Springs Retreat id17355 View details | Canada | Communication / Marketing | ||
|
Grail Springs Retreat - spa center with procedures from immunological therapy, energy work, work with the body, vibro -acoustics to the spiritual leadership. Grail Springs Retreat corporate office is located in 2004 Bay Lake Rd, Bancroft, Ontario, K0L 1C0, Canada and has 20 employees. |
|||||
| Ransomware | Rural Health Services id17354 View details | United States | Healthcare / Pharma | ||
|
Rural Health Services (RHS) (founded in 1971) has provided a wide array of primary and preventive healthcare services to the population of Aiken County and surrounding areas. RHS is a private, non-profit, Federally Qualified Health Center (FQHC). Rural Health Services corporate office is located in 120 Darlington Dr, Aiken, South Carolina, 29803, United States and has 100 employees. |
|||||
| Ransomware | Adler Shine LLP id17353 View details | United Kingdom | Communication / Marketing | ||
|
Adler Shine LLP (founded in 1986) - the company provides the processing of AIM & ISDX market transactions, an outsort for business processes, tax management services, the organization of mass events with the participation of famous personalities. Adler Shine LLP corporate office is located in Aston House, Cornwall Avenue, London N3 1LF LLP No. OC301724, UK. The total amount of data leakage is 332.20 GB |
|||||
| Ransomware | SimonMed Imaging id17352 View details | United States | Healthcare / Pharma | ||
|
SimonMed Imaging (founded in 2003) is an outpatient medical imaging provider operating across United States with over 150 accredited facilities that are ACR-RADSITE certified with certified technologists and equipment. SimonMed Imaging corporate office is located in 16220 N Scottsdale Rd Ste 600, Scottsdale, Arizona, 85254, United States and has 2,030 employees. The total amount of data leakage is 212.616 GB |
|||||
| Ransomware | PAD Aviation Technics GmbH id17351 View details | Germany | IT | ||
|
PAD Aviation Technics GmbH (founded in 2012) offers a wide range of services on, Airbus A320 Family CEO & NEO, BOEING 737 CL, NG & MAX and Bombardier Dash 8-Q400 aircraft covering all aspects of line & base maintenance in conjunction with a modern hangar facility. PAD Aviation Technics GmbH corporate office is located in Flughafenstrasse 33 D-33142 Büren-Ahden Germany. |
|||||
| Ransomware | Serenity Salon & Spa id17350 View details | United States | Services | ||
|
Serenity Salon & Spa offers services such as - hair services, skin care, waxing services, massage services, nail services. Serenity Salon & Spa corporate office is located in 15270 N Oracle Rd Ste B182, Tucson, Arizona, 85739, United States and has 6 employees. |
|||||
| Ransomware | Michael’s Hair Body Mind id17349 View details | Canada | Services | ||
|
Michael’s Hair Body Mind (founded in 1959) - salon for exemplary hair and beauty services. Michael's Hair Body Mind corporate office is located in 1735 Lakeshore Rd W, Mississauga, Ontario, L5J 1J4, Canada and has 16 employees. |
|||||
| Ransomware | Greenwich Medical Spa id17348 View details | United States | Healthcare / Pharma | ||
|
Greenwich Medical Spa (founded in 2005) specializes in injectables, body contouring, laser hair removal, and skin rejuvenation. Greenwich Medical Spa corporate office is located in 1285 E Putnam Ave, Riverside, Connecticut, 06878, United States and has 23 employees. |
|||||
| Ransomware | Brockway Hair Design id17305 View details | United States | Education | ||
|
Brockway Hair Design offers full service salons specializing in women's and men's cuts, color, hi-lites, texture, and hair treatments. Brockway Hair Design corporate office is located in 9260 Sierra College Blvd Ste 350, Roseville, California, 95661, United States and has 26 employees. |
|||||
| Ransomware | True World Foods id17304 View details | United States | Agriculture / Food | ||
|
True World Foods (founded in 1975) global supplier of fresh and frozen products. True World Foods corporate office is located in 24 Link Dr, Rockleigh, New Jersey, 07647, United States and has 371 employees. |
|||||
| Ransomware | MEDES College id17303 View details | Canada | Education | ||
|
MEDES College offers a range of beauty and wellness education programs. The institution targets individuals seeking to pursue a career in the spa and wellness industry. In addition to educational services, they also provide spa treatments, catering to clients who are interested in relaxation and beauty services. Medes College corporate office is located in 1040 Champlain St Ste 300, Dieppe, New Brunswick, E1A 8L8, Canada and has 21 employees. |
|||||
| Ransomware | Glow Medi Spa id17302 View details | Canada | Healthcare / Pharma | ||
|
Glow Medi Spa - spa center with medical services. Glow Medi Spa corporate office is located in 129 Yorkville Ave Fl 4, Toronto, Ontario, M5R 1C4, Canada and has 10 employees. |
|||||
| Ransomware | Fayez Spa id17082 View details | Canada | Communication / Marketing | ||
|
Fayez Spa - the company provides services of spa-therapists and stylists, anti-aging and relaxing procedures including spa kuhnya, in addition, conducts anti-aging treatment including anti-aging injections. Fayez Spa corporate office is located in 2224 Wharncliffe Rd S, London, Ontario, N6P 1L1, Canada and has 24 employees. |
|||||
| Ransomware | Dolmor Salon id17081 View details | Canada | Services | ||
|
Dolmor Salon (founded in 1952) - services of hairdressers and stylists. Dolmor Salon corporate office is located in 42 Kent St N, Simcoe, Ontario, N3Y 3S2, Canada and has 11 employees. |
|||||
| Ransomware | Beauty Works Spa id17080 View details | Canada | Healthcare / Pharma | ||
|
Beauty Works Spa - full service day spa, offering medical treatments, esthetics, massage & body treatments. Beauty Works Spa corporate office is located in 615 Sidney St, Belleville, Ontario, K8P 4A7, Canada and has 19 employees. |
|||||
| Ransomware | Trimaco id17079 View details | United States | Communication / Marketing | ||
|
Trimaco (founded in 1906) is a manufacturer and worldwide distributor of surface protection and cleaning supplies to the construction, home improvement, and marine industries. Trimaco corporate office is located in 2300 Gateway Centre Blvd Ste 200, Morrisville, North Carolina, 27560, United States and has 224 employees. The total amount of data leakage is 228.10 GB |
|||||
| Ransomware | Miles Industries id16978 View details | United Kingdom | Construction / Real Estate | ||
|
Miles Industries (founded in 1983) company provides services for the design, decoration and reconstruction of the construction environment. Miles Industries corporate office is located in Miles House Sherwood Rd, Bromsgrove, Worcestershire, B60 3DR, United Kingdom and has 24 employees. |
|||||
| Ransomware | Addison Saws id16977 View details | United Kingdom | Manufacturing / Engineering | ||
|
Addison Saws (founded 1956) specializes in providing a wide range of industrial metal cutting solutions, including bandsaws, cold saws, tube benders, laser cutters, and saw blades for the metal cutting industry. Addison Saws corporate office is located in Addison Saws Ltd , Attwood Street, Lye , Stourbridge , UK. |
|||||
| Ransomware | English Braids id16976 View details | United Kingdom | Communication / Marketing | ||
|
English Braids (founded in 1972) is a UK rope manufacturer and global supplier, able to offer a vast range of stock products and bespoke technical rope solutions. English Braids corporate office is located in Spring Lane, Malvern, Worcestershire, WR14 1AL, UK |
|||||
| Ransomware | Aden Footwear id16975 View details | Canada | Retail / E-commerce | ||
|
Aden Footwear & Fashion shoe store with departments for men, women and children in a space of 10,000 square feet. Aden Footwear corporate office is located in 669 Dundas St, Woodstock, Ontario, N4S 1E5, Canada and has 6 employees. |
|||||
| Ransomware | NG Automatics id16974 View details | United Kingdom | Retail / E-commerce | ||
|
NG Automatics (founded in 1998) - company installing automated door systems including sliding and swing doors, aluminium shop fronts and access doors for people with disabilities. NG Automatics corporate office is located in Hope House Farm Barns, Martley, Worcester, WR6 6QThe, UK. |
|||||
| Ransomware | Philip Laney & Jolly id16973 View details | United Kingdom | Construction / Real Estate | ||
|
Philip Laney & Jolly (founded in 1966) real estate agency, including lease and management services. Philip Laney & Jolly corporate office is located in 23 Worcester, RoadGreat Malvern, Worcestershire, WR14 4QY, UK The total amount of data leakage is 391.00 GB |
|||||
| Ransomware | ARDEX Australia id16972 View details | Australia | Communication / Marketing | ||
|
ARDEX Australia - company offers engineering products and systems in areas such as: alignment of floor and adhesive, tiles and natural stone systems, leafy and liquid waterproofing membranes, general design and decorative surfaces. ARDEX Australia corporate office is located in 20 Powers Rd, Seven Hills, New South Wales, 2147, Australia and has 139 employees. |
|||||
| Ransomware | Berman Brothers id16788 View details | United States | Manufacturing / Engineering | ||
|
Berman Brothers is the family-owned & operated scrap metal recycling facility, metal sales, and custom metal fabrication shop in Jacksonville. Berman Brothers corporate office is located in 2500 Evergreen Ave, Jacksonville, Florida, 32206, United States and has 81 employees. |
|||||
| Ransomware | Chappell Schools id16787 View details | United States | Education | ||
|
Chappell Schools - the children's center providing an extensive range of programs for the development of the child. Chappell Schools corporate office is located in 8400 Baycenter Rd, Jacksonville, Florida, 32256, United States and has 115 employees. |
|||||
| Ransomware | Safco International Gen Trading id16786 View details | United Arab Emirates | Agriculture / Food | ||
|
Safco International Gen Trading - the company in the UAE produces food and is a supplier in the FoodService and HoReCA industry in the UAE and abroad. Safco International Gen Trading corporate office is located in Dubai Investment Park Ii, Dubai, United Arab Emirates and has 543 employees. The total amount of data leakage is 506.9 GB |
|||||
| Ransomware | Hospital El Cruce id16785 View details | Argentina | Healthcare / Pharma | ||
|
Hospital El Cruce has 130 beds and offers a wide range of medical services, such as advanced diagnostic tests and highly specialized surgical procedures. Hospital El Cruce corporate office is located in 5401 Av. Calchaqui, Florencio Varela, Buenos Aires, 1888, Argentina and has 116 employees. The total amount of data leakage is 761.60 GB |
|||||
| Ransomware | D & M Trim id16725 View details | United States | Communication / Marketing | — | |
|
D & M Trim, Inc.is a North Florida Based trim company, full service contractor with broad experience in private – sector clients. D & M Trim corporate office is located in 1607 Lucas Ave, Green Cove Springs, Florida, 32043, United States and has 30 employees. |
|||||
| Ransomware | Delta Fabrication and Machine, Inc id16726 View details | United States | Manufacturing / Engineering | — | |
|
Delta Fabrication and Machine, Inc (founded in 1989) - the company offers ready -made solutions that cover all parts of construction and maintenance, including the pre -construction design, purchases and logistics, installation of metal structures, prefabricated pipelines, mechanical design and installation, as well as project management, covering such industries as the production of electricity, automotive industry, aerospace industries , the production of metals and woodworking. Delta Fabrication & Machine corporate office is located in 1379 County Road 2110, Daingerfield, Texas, 75638, United States and has 315 employees |
|||||
| Ransomware | Prestige Maintenance USA id16678 View details | United States | Communication / Marketing | ||
|
Prestige Maintenance USA company betrays cleaning services both in the industrial and in the private sector. Prestige Maintenance USA corporate office is located in 1808 10th St Ste 300, Plano, Texas, 75074, United States and has 3,000 employees. |
|||||
| Ransomware | Indus Towers id16658 View details | India | Telecommunications | ||
|
Indus Towers (founded in 2007), based in Gurgaon, India, is a telecommunications infrastructure provider managing telecom towers and networks. Indus Towers playing a crucial role in the telecommunications landscape in India. Indus Towers corporate office is located in 2nd & 3rd floor C Scheme, Ashok Nagar, Rajasthan, 302001, India and has 3,554 employees. |
|||||
| Ransomware | The Metropolitan Borough of Gateshead id16657 View details | United Kingdom | Public Sector | ||
|
The Metropolitan Borough of Gateshead is a metropolitan borough in the metropolitan county of Tyne and Wear, England. It includes Gateshead, Rowlands Gill, Whickham, Blaydon, Ryton, Felling, Birtley, Pelaw, Dunston and Low Fell. The borough forms part of the Tyneside conurbation, centred on Newcastle upon Tyne. At the 2021 census, the borough had a population of 196154. Gateshead Council office is located in 12 Gladstone Ter, Gateshead, Tyne and Wear, NE8 4DY, United Kingdom and has 684 employees. |
|||||
| Ransomware | AVI Southeast id16656 View details | United States | Public Sector | ||
|
AVI Southeast is a wholly owned audio visual system integrator with over 20 years of experience with design, installation and top customer support throughout the Southeast and United States. AVI corporate office is located in 9675 W 76th St Ste 130, Eden Prairie, Minnesota, 55344, United States and has 1,000 employees. |
|||||
| Ransomware | Rent-2-Own id16556 View details | United States | Retail / E-commerce | ||
|
Rent-2-Own has rent to own furniture, rent to own TV, rent to own computers, and we rent appliances too. 32 Ohio and Kentucky rental stores. Rent 2 Own corporate office is located in 1369 W Ohio Pike, Amelia, Ohio, 45102, United States and has 360 employees. |
|||||
| Ransomware | Albion College id16286 View details | United States | Education | ||
|
Albion College (founded in 1850) offers bachelor’s degrees in business, the humanities, fine arts, natural sciences, and social sciences. It provides study-abroad programs in Europe, Latin America, Israel, Africa, Asia, and Australia. About 1,500 students are currently studying. Albion College corporate office is located Albion, Michigan, United States and has 412 employees. |
|||||
| Ransomware | Broker Educational Sales & Training id16226 View details | United States | Education | ||
|
Broker Educational Sales & Training (founded in 1986) has been providing insurance continuing education (CE) to financial and insurance professionals nationwide. Broker Educational Sales & Training corporate office is located in 7137 Congress St, New Port Richey, Florida, 34653, United States and has 27 employees. |
|||||
| Ransomware | Westfield Fire Department id16085 View details | United States | Public Sector | ||
|
Westfield Fire Department (founded in 1931) is located in Middletown, Connecticut. They provide fire prevention, fire protection, medical and rescue services. Westfield Fire Department corporate office is located in 653 East St, Middletown, Connecticut, 06457, United States and has 36 employees. |
|||||
| Ransomware | North Los Angeles County Regional Center id16084 View details | United States | Public Sector | ||
|
North Los Angeles County Regional Center - the company provides legal support for persons with developmental disabilities. North Los Angeles County Regional Center corporate office is located in 9200 Oakdale Ave Ste 100, Chatsworth, California, 91311, United States and has 360 employees. The total amount of data leakage is 600.8 GB |
|||||
| Ransomware | Clarkson Insurance Group id16083 View details | United States | Finance / Legal / Insurance | ||
|
Clarkson Insurance Group - insurance broker for business, families and private individuals. Clarkson Insurance Group corporate office is located in 401 W Main St Ste 1500, Louisville, Kentucky, 40202, United States and has 27 employees. The total amount of data leakage is 115.9 GB |
|||||
| Ransomware | Inmobiliaria Armas id15973 View details | Chile | Construction / Real Estate | ||
|
Inmobiliaria Armas is a company that operates in the Real Estate industry. Inmobiliaria Armas corporate office is located in 1200 Avenida Manquehue Sur, Las Condes, Santiago Metropolitan, Chile and has 398 employees. |
|||||
| Ransomware | Bergerhof id15972 View details | Netherlands | Transportation / Travel / Logistics | ||
|
Bergerhof (founded 1973) - transport company providing passenger transport services. Bergerhof corporate office is located in 78 Wilhelminastraat, Mierlo, Er 5731, NL. |
|||||
| Ransomware | Ainsworth Game Technology Limited id15971 View details | United States | IT | ||
|
Ainsworth Game Technology Limited (founded 1995) is a manufacturer and supplier of gaming machines, software and related equipment. Ainsworth Game Technology distributes a number of gaming products and related games through its sales and distribution offices in Australia, New Zealand, Asia, the United States and Europe. Ainsworth Game Technology corporate office is located in 10 Holker St, Newington, New South Wales, 2127, Australia and has 304 employees. The total amount of data leakage is 852.40 GB |
|||||
| Ransomware | Brodsky Renehan Pearlstein & Bouquet, Chartered id15896 View details | United States | Finance / Legal / Insurance | ||
|
Brodsky Renehan Pearlstein & Bouquet, Chartered is one of Maryland and Washington, DC's divorce and family law litigation firms. Brodsky Renehan Pearlstein & Bouquet corporate office is located in 16061 Comprint Cir, Gaithersburg, Maryland, 20877, United States and has 17 employees. The total amount of data leakage is 347.20 CB |
|||||
| Ransomware | Levicoff Law Firm, P.C id15894 View details | United States | Finance / Legal / Insurance | ||
|
The Levicoff Law Firm, P.C. - handle civil litigation matters of virtually all kinds including accident and injury cases, construction matters, insurance problems, employment issues, as well as contract disputes, commercial tort claims, and generally any form of litigation a business may confront. The Levicoff Law Firm corporate office is located in 4 Ppg Pl Ste 200, Pittsburgh, Pennsylvania, 15222, United States and has 11 employees. The total amount of data leakage is 246.6 GB. * : The poor leadership team begged us for 1000$ to solve their problem and keep their sensitive data safe. It was a scarce case with such a stupid offer. |
|||||
| Ransomware | Avico Spice id15794 View details | United States | Communication / Marketing | ||
|
Avico Spice is located in New York State. Packers of spices, grated cheese products, fruit and nut products and flavorings. These products are sold in various sizes. The company was previously known as A. Vitagliano & Company, which was established in 1926. |
|||||
| Ransomware | Down East Granite id15793 View details | United States | Other | ||
|
Down East Granite is currently Central Pennsylvania’s fabricator of Granite, Quartz, Corian®, Dekton and Other Natural Stone surfaces. Down East Granite is currently Central Pennsylvania’s fabricator of Granite, Quartz, Corian®, Dekton and Other Natural Stone surfaces. |
|||||
| Ransomware | Wiley Metal Fabricating id15792 View details | United States | Manufacturing / Engineering | ||
|
Wiley Metal Fabricating - the company is engaged in the manufacture of sheet and structural metal. Wiley Metal Fabricating corporate office is located in 4589 N Wabash Rd 46952, Marion, Indiana, 46952, United States and has 96 employees. |
|||||
| Ransomware | Kela Health id15639 View details | Belgium | Healthcare / Pharma | ||
|
Kela Health (founded 1941) - the developer and manufacturer of pharmaceuticals and food additives in the field of global health of animals, as well as develops and produces a limited series of pharmaceuticals and food additives for people. Kela Health corporate office is located in 48 Sint-lenaartseweg, Hoogstraten, Antwerpen 2320, BE. |
|||||
| Ransomware | Fancy Foods id15638 View details | United States | Agriculture / Food | ||
|
Fancy Foods, Inc. is a food distribution company serving as a diversified supplier of protein food products and services to the retail, wholesale, and foodservice sectors in the New York, New Jersey, and Connecticut markets. Fancy Foods corporate office is located in 355 Food Center Dr Ste B12, Bronx, New York, 10474, United States and has 249 employees. |
|||||
| Ransomware | Perfection Plus Services Inc id15623 View details | United States | Services | ||
|
Perfection Plus Services Inc is a building materials company based out of 203 S Old Wire Rd, Wildwood, Florida, United States. |
|||||
| Ransomware | RDS Electric id15532 View details | United States | Communication / Marketing | ||
|
RDS Electric has been providing electrical services in the Arizona area. RDS Electric corporate office is located in 6618 N 58th Dr, Glendale, Arizona, 85301, United States and has 31 employees. |
|||||
| Ransomware | Maxeon id15406 View details | Singapore | Energy | ||
|
Maxeon is a solar energy innovation company that designs, manufactures and markets advanced solar panels and solutions worldwide under the Maxeon and SunPower brands. Maxeon corporate office is located in Marina Bay Financial Centre no. 05-02 8 Marina Blvd, Singapore, Central Singapore, 18981, Singapore and has 3,888 employees. |
|||||
| Ransomware | Apple Electric Ltd id15385 View details | United States | Construction / Real Estate | ||
|
Apple Electric Ltd. is solution electrical contractor providing a wide range of electrical, electronic and communications services to commercial and industrial customers. Apple Electrical Contractors corporate office is located in 7540 Andrews Hwy, Odessa, Texas, 79765, United States and has 40 employees. |
|||||
| Ransomware | LEGO Construction Co id15384 View details | United States | Construction / Real Estate | ||
|
LEGO Construction Co. is a Florida-based construction firm headquartered in the heart of Miami, specialize in healthcare, education, federal projects, correctional facilities, transportation, and historic preservation. LEGO Construction corporate office is located in 1011 Sunnybrook Rd Ste 905, Miami, Florida, 33136, United States and has 34 employees. The total amount of data leakage is 849.5 GB |
|||||
| Ransomware | Logistical Software Ltd id15383 View details | United Kingdom | IT | ||
|
Logistical Software Ltd. - creating information solutions for logistics management for freight transport and beyond. Logistical Software Ltd. corporate office is located in Rainham, Essex RM13 8RE, GB. |
|||||
| Ransomware | Manens-Tifs SpA id15382 View details | Italy | Manufacturing / Engineering | ||
|
Manens-Tifs SpA - italian engineering consulting company specializing in engineering and project management. Manens-Tifs SpA corporate office is located in 56 Corso Stati Uniti N, Padova, Veneto, 35127, Italy and has 260 employees. |
|||||
| Ransomware | DynamicSystems id15297 View details | United States | Services | ||
|
Dynamic Systems (founded in 1991) - provides technology solutions that make data management simple. Dynamic Systems corporate office is located in 880 N Park View Dr, El Segundo, California, 90245, United States and has 350 employees. |
|||||
| Ransomware | Marisa S.A id15227 View details | Brazil | Retail / E-commerce | ||
|
Marisa S.A. is the largest Brazilian department store chain specialized in women’s clothing. Marisa corporate office is located in 422/432 R James Holland, Sao Paulo, Sao Paulo, 1138000, Brazil and has 15,104 employees. |
|||||
| Ransomware | Alliance Technical Group id15206 View details | United States | IT | ||
|
Alliance Technical Group - company provides solutions problems of environmental management and compliance for some of the foremost companies and brands in North America. Alliance Technical Group corporate office is located in 255 Grant St SE Ste 600, Decatur, Alabama, 35601, United States and has 1,400 employees. The total amount of data leakage is 1.2 TB |
|||||
| Ransomware | Jomar Electrical Contractors id15205 View details | United States | Construction / Real Estate | ||
|
Jomar Electrical Contractors the company is engaged in the construction of electrical systems in the commercial construction industry. Jomar corporate office is located in 770 N Sam Houston Pkwy E, Houston, Texas, 77060, United States and has 306 employees. The total amount of data leakage is 797.2 GB |
|||||
| Ransomware | Howell Electric Inc id15204 View details | United States | Construction / Real Estate | ||
|
Howell Electric Inc. ( founded 1986 ) is a electrical contractor company. It offers design-build construction, security, access control, & CCTV systems. Howell Electric corporate office is located in 3390 Viso Ct, Santa Clara, California, 95054, United States and has 104 employees. The total amount of data leakage is 189.9 GB |
|||||
| Ransomware | McMillan Electric Company id15156 View details | United States | Communication / Marketing | ||
|
McMillan Electric Company (founded in 1976) is a custom motor and motor products manufacturer for OEMs. MCMILLAN ELECTRIC corporate office is located in 400 Best Rd, Woodville, Wisconsin, 54028, United States and has 226 employees |
|||||
| Ransomware | International University of Sarajevo id15143 View details | Bosnia and Herzegovina | Education | ||
|
The International University of Sarajevo (IUS founded 2004) is a private university located in the capital city Sarajevo, Bosnia and Herzegovina. IUS has 1650 students from 55 countries and faculty members from 20 countries. International University of Sarajevo corporate office is located in 15 Hrasnika Cesta, Sarajevo, Federation of Bosnia and Herzegovina, Bosnia and Herzegowina and has 263 employees. |
|||||
| Ransomware | Whitaker Construction Group id15142 View details | United States | Construction / Real Estate | ||
|
Whitaker Construction Group Inc is a company that operates in the commercial & residential construction industry. Whitaker Construction Group corporate office is located in 2752 Concrete Ct, Paso Robles, California, 93446, United States and has 19 employees. |
|||||
| Ransomware | United Sleep Diagnostics id15109 View details | United States | Public Sector | ||
|
United Sleep Diagnostics specializes in the monitoring of sleep disorders. United Sleep Diagnostics corporate office is located in 3635 Bell Blvd Ste 202, Bayside, New York, 11361, United States and has 106 employees. The total amount of data leakage is 1.20 TB |
|||||
| Ransomware | Spirit Lake Community School District id15056 View details | United States | Education | ||
|
The Spirit Lake Community School District is a rural public school district based in Spirit Lake, Iowa, United States. The district includes three schools: Spirit Lake High School, Spirit Lake Middle School, Spirit Lake Elementary School. At the beginning of 2024, the number of students enrolled was 1304 people, the number of teachers was 100 people. |
|||||
| Ransomware | Lakesight Technologies Information id15012 View details | Germany | IT | ||
|
Lakesight Technologies Information - company manufactures a machine vision products portfolio that focuses on smart cameras, area scan cameras, line scan cameras, and vision controllers for various industrial applications; and high-speed cameras that are used for industrial and scientific applications, as well as in other high-performance applications. Corporate office is located in Unterschleißheim, Bayern, Germany. |
|||||
| Ransomware | Island Coastal Services Ltd id15011 View details | Canada | Services | ||
|
Island Coastal Services Ltd. is an earthmoving construction company. Island Coastal Services corporate office is located in 155 Belvedere Ave, Charlottetown, Prince Edward Island, C1A 2Y9, Canada and has 86 employees. |
|||||
| Ransomware | Automha id14886 View details | Italy | Transportation / Travel / Logistics | ||
|
Automha (founded 1979) - the company develops atomized warehouse storage systems. Automha corporate office is located in 6 Via Emilia, Azzano San Paolo, Lombardy, 24052, Italy and has 114 employees. The total amount of data leakage is 308.9 GB |
|||||
| Ransomware | American Mechanical, inc id14885 View details | United States | Manufacturing / Engineering | ||
|
American Mechanical, inc. - company design, install and service heating, ventilating and air-conditioning systems for the commercial and industrial marketplace. The company's corporate office is located at 1275 Boulevard Way, Walnut Creek CA, 94595 |
|||||
| Ransomware | American Medical Billing id14884 View details | United States | Healthcare / Pharma | ||
|
American Medical Billing (founded in 1994) provides complete medical billing services to health care providers. American Medical Billing corporate office is located in 100 E Irving Park Rd Ste 200, Roselle, Illinois, 60172, United States and has 19 employees. |
|||||
| Ransomware | Ideker id14773 View details | United States | Construction / Real Estate | ||
|
Ideker, Inc. is a family owned construction company specializing in heavy highway construction. Ideker corporate office is located in 4614 S 40th St, Saint Joseph, Missouri, 64503, United States and has 90 employees. |
|||||
| Ransomware | Ultimate Removal id14772 View details | United States | Construction / Real Estate | ||
|
Ultimate Removal, Inc. is a demolition contractor in the tenant improvement niche of commercial construction. Ultimate Removal corporate office is located in 2168 Pomona Blvd, Pomona, California, 91768, United States and has 88 employees. The total amount of data leakage is 952.40 GB |
|||||
| Ransomware | Inner City Education Foundation id14771 View details | United States | Education | ||
|
Inner City Education Foundation (ICEF) operates 7 schools educating approximately 3,000 students. The ICEF corporate office is located in 3855 W Slauson Ave, Los Angeles, California, 90043, United States and has 259 employees. |
|||||