Ransomware Group intelligence
Medusa
InactiveTrack Medusa with 521 published victims and 12 known leak locations in a single intelligence view.
Overview
Medusa is tracked by Breach House as a ransomware group with 521 published victims.
United States is currently the most targeted country in this dataset.
12 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (12)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 10 | Onion service | Down checked 2h ago | hupxs7ps7md24kpz4lwsbra64abgxjx3pcc2wuca5ibawf2g5hlpfyqd.onion |
| Leak location 8 | Onion service | Down checked 2h ago | cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion |
| Leak location 6 | Onion service | Down checked 2h ago | s7lmmhlt3iwnwirxvgjidl6omcblvw2rg75txjfduy73kx5brlmiulad.onion |
| Leak location 12 | Onion service | Down checked 2h ago | 7aqabivkwmpvjkyefonf3gpy5gsubopqni7kcirsrq3pflckxq5zz4id.onion |
| Leak location 11 | Onion service | Down checked 2h ago | 62foekhv5humjrfwjdyd2dgextpbf5i7obguhwvfoghmu3nxpkmxlcid.onion |
| Leak location 4 | Onion service | Down checked 2h ago | dlmfciajg5s4vliyo5dhs5jyzhi2xr2fnkebul46lpf4xudtqiue4nid.onion |
| Leak location 7 | Web location | Down checked 2h ago | 45.9.148.39 |
| Leak location 5 | Onion service | Down checked 2h ago | kyfiw76eol6ph2mq7pi5e5tdvce37bicddhai62qhdc5ja6jdchz4qqd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion |
| Leak location 9 | Onion service | Down checked 2h ago | xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion |
| Leak location 2 | Onion service | Down checked 2h ago | medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion |
| Leak location 1 | Onion service | Down checked 2h ago | medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion |
Top Activity Sectors (17)
- Communication / Marketing 105
- Services 55
- Public Sector 54
- Healthcare / Pharma 52
- Education 40
- Finance / Legal / Insurance 32
- Construction / Real Estate 31
- IT 30
- Manufacturing / Engineering 28
- Retail / E-commerce 20
- Hospitality / Food & Beverage / Tourism 17
- Energy 13
- Transportation / Travel / Logistics 13
- Agriculture / Food 9
- NGOs / Associations 7
- Telecommunications 6
- Not identified 4
Typical Attacks (64)
▼How Medusa typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Medusa Group, Medusa Ransomware.
-
T1583.006 Web Services Resource Development
What they do: Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions.
What that means: Adversaries may register for web services that can be used during targeting.
-
T1585.001 Social Media Accounts Resource Development
What they do: Medusa Group has created social media accounts including Telegram and X to publicize their activities.
What that means: Adversaries may create and cultivate social media accounts that can be used during targeting.
-
T1585.002 Email Accounts Resource Development
What they do: Medusa Group has created email accounts used in ransomware negotiations.
What that means: Adversaries may create email accounts that can be used during targeting.
-
T1588.002 Tool Resource Development
What they do: Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
T1608.002 Upload Tool Resource Development
What they do: Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise.
What that means: Adversaries may upload tools to third-party or adversary controlled infrastructure to make it accessible during targeting.
-
T1650 Acquire Access Resource Development
What they do: Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs).
What that means: Adversaries may purchase or otherwise acquire an existing access to a target system or network.
-
What they do: Medusa Group has utilized compromised legitimate local and domain accounts within the victim environment to facilitate remote access and lateral movement sometimes in combination with PsExec.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Medusa Group has leveraged public facing vulnerabilities in their campaigns against victim organizations to gain initial access.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1047 Windows Management Instrumentation Execution
What they do: Medusa Group has utilized Windows Management Instrumentation to query system information.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: Medusa Group has leveraged PowerShell for execution and defense evasion.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Medusa Group has used Windows Command Prompt to control and execute commands on the system to include ingress, network, and filesystem enumeration activities.
What that means: Adversaries may abuse the Windows command shell for execution.
-
What they do: Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy.
What that means: Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network.
-
T1106 Native API Execution
What they do: Medusa Group has leveraged Windows Native API functions to execute payloads.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1559 Inter-Process Communication Execution
What they do: Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication.
What that means: Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution.
-
T1559.001 Component Object Model Execution
What they do: Medusa Group has leveraged Component Object Model (COM) to bypass UAC.
What that means: Adversaries may use the Windows Component Object Model (COM) for local code execution.
-
T1569.002 Service Execution Execution
What they do: Medusa Group has utilized PsExec to execute scripts and commands within victim environments.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Medusa Group has modified Registry keys to elevate privileges, maintain persistence and allow remote access.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1136.002 Domain Account Persistence
What they do: Medusa Group has created a domain account within the victim environment.
What that means: Adversaries may create a domain account to maintain access to victim systems.
-
T1505.003 Web Shell Persistence
What they do: Medusa Group has utilized webshells to an exploited Microsoft Exchange Server.
What that means: Adversaries may backdoor web servers with web shells to establish persistent access to systems.
-
What they do: Medusa Group has used vulnerable or signed drivers to modify security solutions on victim devices.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027.002 Software Packing Stealth
What they do: Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1027.010 Command Obfuscation Stealth
What they do: Medusa Group has obfuscated PowerShell scripts with Base64 encoding.
What that means: Adversaries may obfuscate content during command execution to impede detection.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Medusa Ransomware has utilized XOR encrypted strings.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.003 Clear Command History Stealth
What they do: Medusa Group has cleared command history by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.
What that means: In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.
-
T1070.004 File Deletion Stealth
What they do: Medusa Group has deleted previously installed tools.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1218.014 MMC Stealth
What they do: Medusa Group has leveraged Microsoft Management Console (MMC) to facilitate lateral movement and to interact locally or remotely with victim devices using the command `mmc.exe compmgmt.msc /computer:{hostname/ip}`.
What that means: Adversaries may abuse mmc.exe to proxy execution of malicious .msc files.
-
T1564.003 Hidden Window Stealth
What they do: Medusa Group has utilized the `ShowWindow` API function to hide the current window.
What that means: Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
-
T1679 Selective Exclusion Stealth
What they do: Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device.
What that means: Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution.
-
T1553.002 Code Signing Defense Impairment
What they do: Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools.
What that means: Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1686 Disable or Modify System Firewall Defense Impairment
What they do: Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings.
What that means: Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action.
-
T1690 Prevent Command History Logging Defense Impairment
What they do: Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.
What that means: Adversaries may impair command history logging to hide commands they run on a compromised system.
-
T1003.001 LSASS Memory Credential Access
What they do: Medusa Group has leveraged Mimikatz to dump LSASS to harvest credentials.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1003.003 NTDS Credential Access
What they do: Medusa Group has accessed the ntds.dit file to engage in credential dumping.
What that means: Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights.
-
T1007 System Service Discovery Discovery
What they do: Medusa Ransomware has leveraged an encoded list of services that it designates for termination.
What that means: Adversaries may try to gather information about registered local system services.
-
T1016 System Network Configuration Discovery Discovery
What they do: Medusa Group has obtained host network details utilizing the command `cmd.exe /c ipconfig /all`.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Medusa Group has used PDQ Inventory to get an inventory of the endpoints on the network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1033 System Owner/User Discovery Discovery
What they do: Medusa Group has utilized PsExec to execute `quser` to discover the user session information.
What that means: Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
-
T1046 Network Service Discovery Discovery
What they do: Medusa Group has the capability to use living off the land (LOTL) binaries to perform network enumeration.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1057 Process Discovery Discovery
What they do: Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1069.002 Domain Groups Discovery
What they do: Medusa Group has utilized the `net group` command to query domain groups within the victim environment.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: Medusa Group has leveraged `cmd.exe` to identify system info `cmd.exe /c systeminfo`.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Medusa Group has searched for files within the victim environment for encryption and exfiltration.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.001 Local Account Discovery
What they do: Medusa Group has leveraged `net user` for account discovery.
What that means: Adversaries may attempt to get a listing of local system accounts.
-
T1124 System Time Discovery Discovery
What they do: Medusa Ransomware has discovered device uptime through `GetTickCount()`.
What that means: An adversary may gather the system time and/or time zone settings from a local or remote system.
-
T1135 Network Share Discovery Discovery
What they do: Medusa Group has identified network shares using `cmd.exe /c net share`.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1518.001 Security Software Discovery Discovery
What they do: Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1652 Device Driver Discovery Discovery
What they do: Medusa Group has queried drivers on the victim device through the command `driverquery`.
What that means: Adversaries may attempt to enumerate local device drivers on a victim host.
-
T1680 Local Storage Discovery Discovery
What they do: Medusa Ransomware has enumerated logical drives on infected hosts.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: Medusa Group has used RDP to conduct lateral movement and exfiltrate data.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1071.001 Web Protocols Command and Control
What they do: Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS).
What that means: Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
-
T1090.003 Multi-hop Proxy Command and Control
What they do: Medusa Group has used TOR nodes for communications.
What that means: Adversaries may chain together multiple proxies to disguise the source of malicious traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1219 Remote Access Tools Command and Control
What they do: Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1573.002 Asymmetric Cryptography Command and Control
What they do: Medusa Group has used HTTPS for command and control.
What that means: Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1529 System Shutdown/Reboot Impact
What they do: Medusa Group has manually turned off and encrypted virtual machines.
What that means: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
-
T1657 Financial Theft Impact
What they do: Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (27)
▼Software Medusa has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
!!!READ_ME_MEDUSA!!!.txt
$$\ $$\ $$$$$$$$\ $$$$$$$\ $$\ $$\ $$$$$$\ $$$$$$\ $$$\ $$$ |$$ _____|$$ __$$\ $$ | $$ |$$ __$$\ $$ __$$\ $$$$\ $$$$ |$$ | $$ | $$ |$$ | $$ |$$ / \__|$$ / $$ | $$\$$\$$ $$ |$$$$$\ $$ | $$ |$$ | $$ |\$$$$$$\ $$$$$$$$ | $$ \$$$ $$ |$$ __| $$ | $$ |$$ | $$ | \____$$\ $$ __$$ | $$ |\$ /$$ |$$ | $$ | $$ |$$ | $$ |$$\ $$ |$$ | $$ | $$ | \_/ $$ |$$$$$$$$\ $$$$$$$ |\$$$$$$ |\$$$$$$ |$$ | $$ | \__| \__|\________|\_______/ \______/ \______/ \__| \__| -----------------------------[ Hello, [snip] !!! ]-------------------------- WHAT HAPPEND? ------------------------------------------------------------ 1. We have PENETRATE your network and COPIED data. * We have penetrated entire network including backup system and researched all about your data. * And we have extracted all of your networks including sub offices and your service clients networks valuable data and copied them to private cloud storage. 2. We have ENCRYPTED some your files. While you are reading this message, it means you found your files and data has been ENCRYPTED by world's strongest ransomware. We have access to all of your sub offices and client service networks but didn't lock them all for your brand and privacy. We can solve this issue sliently and smoothly without 3rd parties and we decided lock only some of your main network only. But don't worry, we can restore everything to the original without harming your business. There is only one possible way to get back your systems and business - CONTACT us via LIVE CHAT and pay for the special MEDUSA DECRYPTOR and DECRYPTION KEYs, Data deletion, Keep silent in media. This MEDUSA DECRYPTOR will restore your entire network, This will take less than 1 business day. WHAT GUARANTEES? --------------------------------------------------------------- We can post your data to the public and send emails to your customers. We have professional OSINTs and media team for leak data to telegram, facebook, twitter channels and top news websites. Have a look about us on twitter. You can suffer significant problems due disastrous consequences, leading to loss of valuable intellectual property and other sensitive information, costly incident response efforts, information misuse/abuse, loss of customer trust, brand and reputational damage, legal and regulatory issues. After paying for the data breach and decryption, we guarantee that your data will never be leaked and this is also for our reputation. YOU should be AWARE! --------------------------------------------------------------- If you're not in main chile office, inform your supervisors and stay calm! We will speak only with an authorized person. It can be the CEO, top management, etc. In case you are not such a person - DON'T CONTACT US! Your decisions and action can result in serious harm to your company! If you do not contact us within 3 days, We will start publish your case to our official blog and everybody will start notice your incident! If you do not contact us within 5 days, We will start publish your case and leak video on all social channels and send emails to your customers! --------------------[ Official blog tor address ]-------------------- Using TOR Browser(https://www.torproject.org/download/): http://medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion/ CONTACT US! ----------------------[ Your company live chat address ]--------------------------- Using TOR Browser(https://www.torproject.org/download/): http://medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion/[snip] Or Use Tox Chat Program(https://qtox.github.io/) Add user with our tox ID and wait 24h : 4AE245548F2A225882951FB14E9BF87EE01A0C10AE159B99D1EA62620D91A372205227254A9F Our support email: ( [email protected] ) Company identification hash: [snip]
!!!READ_ME_MEDUSA!!!_2.txt
$$\ $$\ $$$$$$$$\ $$$$$$$\ $$\ $$\ $$$$$$\ $$$$$$\ $$$\ $$$ |$$ _____|$$ __$$\ $$ | $$ |$$ __$$\ $$ __$$\ $$$$\ $$$$ |$$ | $$ | $$ |$$ | $$ |$$ / \__|$$ / $$ | $$\$$\$$ $$ |$$$$$\ $$ | $$ |$$ | $$ |\$$$$$$\ $$$$$$$$ | $$ \$$$ $$ |$$ __| $$ | $$ |$$ | $$ | \____$$\ $$ __$$ | $$ |\$ /$$ |$$ | $$ | $$ |$$ | $$ |$$\ $$ |$$ | $$ | $$ | \_/ $$ |$$$$$$$$\ $$$$$$$ |\$$$$$$ |\$$$$$$ |$$ | $$ | \__| \__|\________|\_______/ \______/ \______/ \__| \__| -----------------------------[ Hello, [snip] !!! ]-------------------------- Sorry to interrupt your busy business. WHAT HAPPEND? ------------------------------------------------------------ 1. We have PENETRATE your network and COPIED data. We have penetrated your entire network and researched all about your data. And we have copied all of your confidential data and uploaded to private storage. * You're running a highly valued business and your data was very crucial. 2. We have ENCRYPTED your files. While you are reading this message, it means your files and data has been ENCRYPTED by world's strongest ransomware. Your files have encrypted with new military-grade encryption algorithm and you can not decrypt your files. But don't worry, we can decrypt your files. There is only one possible way to get back your computers and servers, keep your privacy safe - CONTACT us via LIVE CHAT and pay for the special MEDUSA DECRYPTOR and DECRYPTION KEYs. This MEDUSA DECRYPTOR will restore your entire network within less than 1 business day. WHAT GUARANTEES? --------------------------------------------------------------- We can post all of your critial data to the public and send emails to your competitors. We have professional OSINTs and media team for leak data to telegram, facebook, twitter channels and top news websites. You can easily search about us. You can suffer significant problems due to disastrous consequences, leading to loss of valuable intellectual property and other sensitive information, costly incident response efforts, information misuse/abuse, loss of customer trust, brand and reputational damage, and legal and regulatory issues. After paying for the data breach and decryption, we guarantee that your data will never be leaked and make everything silent, this is also for our reputation. YOU should be AWARE! --------------------------------------------------------------- We will speak only with an authorized person. It can be the CEO, top management etc. In case you ar not such a person - DON'T CONTACT US! Your decisions and action can result in serious harm to your company! Inform your supervisors and stay calm! If you do not contact us within 48 hours, We will start publish your case to our official blog and everybody will start notice your incident! --------------------[ Telegram channel ]-------------------- https://t.me/+yXOcSjVjI9tjM2E0 --------------------[ Official blog tor address ]-------------------- Using TOR Browser(https://www.torproject.org/download/): http://xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion/ http://cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion/ CONTACT US! ----------------------[ Your company live chat address ]--------------------------- Using TOR Browser(https://www.torproject.org/download/): http://uyku4o2yg34ekvjtszg6gu7cvjzm6hyszhtu7c55iyuzhpr4k5knewyd.onion/[snip] Backup Mirrors: http://5ar4vuckm3k7osdlzskqkaqmqr4jjpmdikuotmlpkrbsxx7ard3xetyd.onion/[snip] --------------------[ Or Use Tox Chat Program(https://utox.org/uTox_win64.exe) ]-------------------- Add user with our tox ID : 061AA6BDE8F6DE6C92F0D6E077359BF6911FCAF80030E82B3A3DB65E63C8011343D34F956FEC Our support email: ( [email protected] ) Company identification hash: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (521)
Search, filter and paginate the victim timeline for Medusa. Showing 201–300 of 521.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | SystemPavers id14770 View details | United States | Public Sector | ||
|
System Pavers is a design and installation company in the outdoor remodel industry. System Pavers inc. corporate office is located in 1570 Brookhollow Dr, Santa Ana, California, 92705, United States and has 496 employees. |
|||||
| Ransomware | World Vision Perú id14743 View details | Peru | Communication / Marketing | ||
|
World Vision Perú (founded in 1994) - christian social action organization aimed at protecting and developing the potential of children. World Vision Perú corporate office is located in 2040 Sánchez Cerro Jesús María, Lima, Lima Province, Peru and has 314 employees. |
|||||
| Ransomware | Construction Systems inc id14742 View details | United States | Construction / Real Estate | ||
|
Construction Systems inc. provides complete commercial renovation and specialties installation services for medical, commercial office, industrial, retail, education and etc. Construction Systems corporate office is located in 2865 E 14th Ave, Columbus, Ohio, 43219, United States and has 105 employees.The total amount of data leakage is 80.80 GB |
|||||
| Ransomware | Østerås Bygg id14731 View details | Norway | Energy | ||
|
Østerås Bygg (founded in 1995) - the company produces and sets climatic walls, facades, internal walls, installation of doors, windows, floors and ceilings, moldings and parquet. Østerås Bygg corporate office is located in 13 Hovfaret, Oslo, Oslo, 0275, Norway. The total amount of data leakage is 125.50 GB |
|||||
| Ransomware | Istrail id14627 View details | Norway | Manufacturing / Engineering | ||
|
Istrail(founded in 1916) is a large mechanical workshop specializing in the production of semi -trailers.Istrail corporate office is located in Nordre Kullerød 17, 3241 Sandefjord, Norway. |
|||||
| Ransomware | Albany College of Pharmacy id14626 View details | United States | Education | ||
|
Albany College of Pharmacy and Health Sciences (formerly Albany College of Pharmacy) is a private, independent college with a campus in Albany, New York. ACPHS is home to approximately 900 students and 115 full-and-part time faculty. Albany College of Pharmacy and Health Sciences corporate office is located in 106 New Scotland Ave Rm Ob211p, Albany, New York, 12208, United States and has 434 employees. |
|||||
| Ransomware | Arelance Group id14625 View details | Spain | IT | ||
|
Arelance Group is a technology consulting company specializing in the development and implementation of comprehensive solutions and support for projects in the field of digital transformation. The company's corporate office is located at PTA. C/ Marie Curie, 3. Edf. Premier II. Campanillas Spain. |
|||||
| Ransomware | Emerson id14571 View details | United States | IT | ||
|
Emerson is a technology, software, and engineering company providing solutions for customers in industrial and commercial industries. Emerson corporate office is located in 8000 W Florissant Ave, St. Louis, Missouri, 63136, United States and has 67,000 employees. This is oracle database of their subsidiary company Zedi. The total amount of data leakage is 938.00 GB |
|||||
| Ransomware | BELL DATA, Inc id14536 View details | Japan | Services | ||
|
BELL DATA, Inc - the company provides rental services for server equipment, hosting services, integration, etc. Head officeis is located in Shinjuku Mitsui Bld.49F, 2-1-1, Nishishinjuku, Shinjuku-ku, Tokyo, 163-0449, Japan. |
|||||
| Ransomware | Travel Alberta id14535 View details | Canada | Transportation / Travel / Logistics | ||
|
Travel Alberta ( founded in 2009 ),is a tourism marketing organization for the province of Alberta. Travel Alberta corporate office is located in 400-1601 9 Ave SE, Calgary, Alberta, T2G 0H4, Canada and has 110 employees. The total amount of data leakage is 799.80 GB |
|||||
| Ransomware | Isola id14517 View details | Norway | Communication / Marketing | ||
|
Isola is a Norwegian manufacturer of building products and solutions for roofs, walls, floors and foundations. Isola corporate office is located in 9 Prestemoen, Porsgrunn, Telemark, 3946, Norway. |
|||||
| Ransomware | Sub-Zero, Wolf, and Cove id14516 View details | United States | Communication / Marketing | ||
|
Sub-Zero, Wolf, and Cove is an American brand of residential major kitchen appliances including refrigeration and preservation products. Sub-Zero, Wolf, and Cove corporate office is located in 4717 Hammersley Rd, Madison, Wisconsin, 53711, United States and has 2,648 employees. The total amount of data leakage is 760.60 GB |
|||||
| Ransomware | Røros Hotell id14486 View details | Norway | Hospitality / Food & Beverage / Tourism | ||
|
Røros Hotell (founded in 1951) - a hotel with a cinema, children's playgrounds and other things. The hotel is located at Roros Hotell (Avd.300), Postboks 67,Økern 0508, OSLO, Norway. The total amount of data leakage is 53.80 GB |
|||||
| Ransomware | Xtera Communications id14478 View details | United Kingdom | Communication / Marketing | ||
|
Xtera Communications (founded in 1951) is an provider of sub-sea telecoms solutions and carries an extensive portfolio of intellectual property. The company supplies both un-repeatered and repeatered systems, using its high performance optical amplifiers to deliver traffic directly inland to cities. Xtera Communications corporate office is located in Bates House Church Rd, London, Greater London, RM3 0SD, United Kingdom and has 103 employees. |
|||||
| Ransomware | Hairstore id14454 View details | Norway | Retail / E-commerce | ||
|
Hairstore supplier of consumables and equipment for the hairdresser. Hairstore corporate office is located in 134 Elveveien, Larvik, Vestfold, 3271, Norway. The total amount of data leakage is 52.30 GB |
|||||
| Ransomware | IP blue Software Solutions id14453 View details | United States | IT | ||
|
IP blue specializes in the development of VoIP softphone products for Windows and Windows Mobile Platforms, Softphones for Cisco IP PBX Platform, 508 compliant Softphones for Visually Impaired and Deaf. P blue Software Solutions corporate office is located in 15 NE Lofting Way, Stuart, Florida, 34996, United States and has 7 employees. |
|||||
| Ransomware | Fritzøe Engros id14389 View details | Norway | Communication / Marketing | ||
|
Fritzøe Engros manufacturer, importer and distributor of wood products. Fritzøe Engros corporate office is located in 10 Øya, Larvik, Vestfold, 3262, Norway. |
|||||
| Ransomware | Wilson & Lafleur id14388 View details | Canada | Retail / E-commerce | ||
|
Wilson & Lafleur (founded in 1909) - literary publishing house also owning a bookstore. Wilson & Lafleur Ltée corporate office is located in 40 Notre-dame Rue E, Montreal, Quebec, H2Y 1B9, Canada and has 19 employees. |
|||||
| Ransomware | Compass Group (2nd attack) id14363 View details | Australia | Telecommunications | ||
|
Our affiliate entered this poor network this morning and messed the computers again! Company kiddy network administrators installed Crowdstrike Falcon EDR everywhere and thought they removed all our connections. Affiliate took the screenshots of DC. Company doesn't care the customer's privacy and also their network security too. One of the poorest company with poor network admins in Australia. |
|||||
| Ransomware | Structural Concepts id14362 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
Structural Concepts (founded in 1973)is a designer and manufacturer of temperature-controlled food & beverage display cases. Structural Concepts corporate office is located in 888 E Porter Rd, Muskegon, Michigan, 49441, United States and has 540 employees. The total amount of data leakage is 603.10 GB |
|||||
| Ransomware | Amerinational Community Services id14354 View details | United States | Services | ||
|
AmeriNat (founded in 1975) provides loan servicing, asset management, underwriting and other services to government agencies, nonprofits, financial institutions and private investors across the United States and Puerto Rico. Amerinational Community Services corporate office is located in 217 S Newton Ave, Albert Lea, Minnesota, 56007, United States and has 109 employees. |
|||||
| Ransomware | Providence Public School Department id14353 View details | United States | Education | ||
|
The Providence Public School Department is the administrative force behind the primary public school district of Providence, Rhode Island. It serves about 21,700 students in pre-K through 12th grade. It has 21 elementary schools, seven middle schools and nine high schools, along with two public charter schools. The total amount of data leakage is 201.40 GB |
|||||
| Ransomware | AZPIRED id14352 View details | United States | Public Sector | ||
|
AZPIRED is outsourcing service center with a number of locations in the Philippines, three offices in Cebu and Cagayan De Oro City. Azpired corporate office is located in 12260 Trail Spring Ct, Las Vegas, Nevada, 89138, United States and has 124 employees. The total amount of data leakage is 205.70 GB |
|||||
| Ransomware | Compass Group id14351 View details | Australia | Services | ||
|
Compass Group is Australia’s largest food and support services company driving. Compass Group Australia corporate office is located in 35-51 Mitchell St, Mcmahons Point, New South Wales, 2060, Australia and has 13,000 employees. The total amount of data leakage is 785.5 GB |
|||||
| Ransomware | Micron Internet id14285 View details | Brazil | Communication / Marketing | ||
|
Micron Internet - provides Internet access services. Micron Internet corporate office is located in 205 Rua Salomao Fadlalah, Ibatiba, Espirito Santo, 29395-000, Brazil and has 63 employees. |
|||||
| Ransomware | TECHNOLOG S.r.l. id14284 View details | Italy | IT | ||
|
TECHNOLOG S.r.l. delivers integrated solutions for interology and industrial automation. TECHNOLOG S.r.l. corporate office is located in 31/a Via Trento, Parma, Emilia-Romagna, Italy. The total amount of data leakage is 439.40 GB |
|||||
| Ransomware | Starr-Iva Water & Sewer District id14262 View details | United States | Communication / Marketing | ||
|
Starr-Iva Water & Sewer District - provides water supply services. Starr-Iva Water and Sewer District corporate office is located in 104 Roy Arnold Rd, Starr, South Carolina, 29684, United States and has 6 employees. |
|||||
| Ransomware | Karakaya Group id14261 View details | Türkiye | Finance / Legal / Insurance | ||
|
Karakaya Group (founded in 1960) - the company is engaged in construction, investment in the entertainment industry, fashion and food. Karakaya Group corporate office is located in Turkey and has 72 employees. The total amount of data leakage is 198.60 GB |
|||||
| Ransomware | Prosolit id14209 View details | Belgium | Communication / Marketing | ||
|
Prosolit (founded in 2004) - provides site development, e-commerce, management software, security software and other IT services. Prosolit corporate office is located in Av. Roi Albert 157/2, 5300 Andenne, Belgium. The total amount of data leakage is 13.07 GB |
|||||
| Ransomware | Grupo Cortefiel id14208 View details | Spain | Retail / E-commerce | ||
|
Grupo Cortefiel is one of Europe's leading fashion retailers operating in the specialised chain segment. Grupo Cortefiel corporate office is located in 51 Avenida Del Llano Castellano, Madrid, Madrid, 28034, Spain and has 3,816 employees. The total amount of data leakage is 724,59 GB |
|||||
| Ransomware | America Voice id14203 View details | United States | Communication / Marketing | ||
|
America Voice provides prepaid telecommunications products. America Voice corporate office is located in 800 S Hope St Ste 120, Los Angeles, California, 90017, United States and has 24 employees. The total amount of data leakage is 134.6 GB |
|||||
| Ransomware | Hospital Episcopal San Lucas id14176 View details | United States | Healthcare / Pharma | ||
|
Hospital Episcopal San Lucas, commonly known as Hospital San Lucas, is a hospital in Ponce, Puerto Rico. Hospital Episcopal San Lucas corporate office is located in PO Box 2027, Ponce, Puerto Rico, 00733, United States and has 131 employees. The total amount of data leakage is 309.00 GB |
|||||
| Ransomware | Kingsport Imaging Systems id14147 View details | United States | Communication / Marketing | ||
|
Kingsport Imaging Systems, Inc. is an independently owned company marketing office equipment as an authorized dealer for Canon USA, Inc. Kingsport Imaging Systems corporate office is located in 200 E Market St, Kingsport, Tennessee, 37660, United States and has 18 employees. |
|||||
| Ransomware | Shomof Group id14141 View details | United States | Construction / Real Estate | ||
|
Shomof Group is the developer to utilize the City’s Adaptive Reuse Ordinance, engaged in reconstruction of office buildings in the center of Los Angeles. Shomof Group real estate portfolio also applies to Los Angeles, Long Beach, Orange County, the San Fernando Valley, and Las Vegas with low-income housing specialization. Shomof Group corporate office is located in 9708 Gilespie St, Las Vegas, Nevada, 89183, United States and has 12 employees. The total amount of data leakage is 130.00 GB |
|||||
| Ransomware | Percento Technologies Internationa id13901 View details | United States | IT | ||
|
Percento Technologies International ( founded in 1999) is an IT services company. Percento Technologies International corporate office is located in 580 Westlake Park Blvd Ste 110, Houston, Texas, 77079, United States and has 20 employees. |
|||||
| Ransomware | The Pyle Group id13843 View details | United States | Services | ||
|
The Pyle Group - provide wealth management solutions to individuals and businesses by acting as their financial quarterback through clarity, counselling and coordination. The total amount of data leakage is 118.8 GB |
|||||
| Ransomware | Camp Susque id13652 View details | United States | Education | ||
|
Camp Susque ( founded in 1947 ) is nestled in the mountains of north-central Pennsylvania - provides to include wilderness trips, family camps, winter camps, homeschool classes, field trips, and retreats and rentals. Camp Susque corporate office is located in 47 Susque Camp Rd, Trout Run, Pennsylvania, 17771, United States and has 16 employees. The total amount of data leakage is 48.9 GB |
|||||
| Ransomware | Ali Gohar id13651 View details | Pakistan | Healthcare / Pharma | ||
|
Ali Gohar & Company (founded in 1950) - are a comprehensive and distribution company that provides services in the pharmaceutical and medical sector. Ali Gohar corporate office is located in 1-b I.i.chundrigar Rd, Karachi, Sindh, 74000, Pakistan and has 375 employees. The total amount of data leakage is 51.9 GB |
|||||
| Ransomware | St. Thomas Aquinas High School id13621 View details | United States | Education | ||
|
St. Thomas Aquinas High School (founded in 1936) is a private, Roman Catholic, college-preparatory high school in Fort Lauderdale, Florida. The school currently enrolls 2,420 students on its 25-acre (100,000 m2) campus. Saint Thomas Aquinas High School corporate office is located in 2801 SW 12th St, Fort Lauderdale, Florida, 33312, United States and has 257 employees. The total amount of data leakage is 103.8 GB |
|||||
| Ransomware | Gentlemen Group GmbH id13594 View details | Germany | Services | ||
|
Gentlemen Group GmbH (founded on January 1, 2021) provides services management, enterprise services (ESM) and management of identification and access (IAM), and technological consultations with an emphasis on strategy, organization, IT, as well as the implementation of decisions and training. Gentlemen Group GmbH corporate office is located in Starnberger Str. 8, 14612 Falkensee, Germany. The total amount of data leakage is 218.4 GB |
|||||
| Ransomware | Owens Valley Career Development Center id13524 View details | United States | IT | ||
|
Owens Valley Career Development Center (founded in 1976) is a dedicated American Indian organization operating under a consortium of Sovereign Nations. Nowadays, OVCDC is a multifaceted business reaching into all aspects of social services and educational services, as well as economic development markets, providing Native American communities with a mechanism for bettering quality of life. Owens Valley Career Development Center corporate office is located in 2574 Diaz Ln, Bishop, California, 93514, United States and has 195 employees. The total amount of data leakage is 300.2 GB |
|||||
| Ransomware | Coffrage LD id13523 View details | Canada | Manufacturing / Engineering | ||
|
Coffrage LD specializes in formwork and concrete placement in commercial industrial, civil engineering, and multi-story building sectors. Coffrage LD corporate office is located in 2621 De La Rotonde Ave, Charny, Quebec, G6X 2M2, Canada and has 88 employees. The total amount of data leakage is 453.4 GB |
|||||
| Ransomware | Vivara id13522 View details | Brazil | Retail / E-commerce | ||
|
Vivara is the largest retailer of jewelry in Brazil, with over 200 stores in major cities. The company also sells a wide range of design watches fr om brands such as Coach, Juicy Couture, Gucci, Lacoste, and more. Vivara corporate office is located in lj 207 Sai so 6580, Guara, Federal District, 71000-000, Brazil and has 1,167 employees. The total amount of data leakage is 1.18Tb and includes confidential data of CEO, top management team, employees and customers. Data also includes company's many hidden illegal activities. |
|||||
| Ransomware | Cedar Technologies id13486 View details | Brazil | IT | ||
|
Cedar Technologies (founded in 2005) is a solutions provider in consulting, technology services and software. Cedro Technologies corporate office is located in 262 Av. João Naves De Avila, Uberlandia, Minas Gerais, 38400000, Brazil and has 133 employees. The total amount of data leakage is 393 GB |
|||||
| Ransomware | American Golf id13485 View details | United States | NGOs / Associations | ||
|
American Golf is one of the operators in the golf industry today. Owner, lessee, and manager of golf courses and country clubs for over 50 years. American Golf corporate office is located in 909 N Pacific Coast Hwy, El Segundo, California, 90245, United States and has 379 employees. The total amount of data leakage is 154.9 GB |
|||||
| Ransomware | Royal Brighton Yacht Club id13484 View details | Australia | Communication / Marketing | ||
|
Royal Brighton Yacht Club is one of Australia's premier yacht clubs, offering a wide range of sailing events and activites year-round. Royal Brighton Yacht Club corporate office is located in PO Box 74, Brighton, Victoria, 3186, Australia and has 19 employees. The total amount of data leakage is 94.2 GB |
|||||
| Ransomware | ValeCard id13483 View details | Brazil | Finance / Legal / Insurance | ||
|
ValeCard (founded in 1995) - provides complex and integrated solutions for managing benefits, finances and frosts. ValeCard corporate office is located in 904 R Machado De Assis, Uberlandia, Minas Gerais, 38400-112, Brazil and has 399 employees. The total amount of data leakage is 107.6 GB |
|||||
| Ransomware | H&H Group id13482 View details | United States | Communication / Marketing | ||
|
The H&H Group is full-service printing and sign shop. The H&H Group corporate office is located in 854 N Prince St, Lancaster, Pennsylvania, 17603, United States and has 40 employees. The total amount of data leakage is 395.8 GB |
|||||
| Ransomware | Jariet Technologies id13481 View details | United States | IT | ||
|
Jariet Technologies, Inc. is a fabless semiconductor company specializing in high-speed data converter technology. Jariet Technologies corporate office is located in 103 W Torrance Blvd, Redondo Beach, California, 90277, United States and has 64 employees.The total amount of data leakage is 325.5 GB |
|||||
| Ransomware | Globes id13480 View details | Israel | Finance / Legal / Insurance | ||
|
Globes - periodical publishing, coverage of Israeli business in management, investment, technology, law, accounting, and marketing. Globes corporate office is located in 53 Etzel St, Rishon LeZiyyon, Central District, 75706, Israel and has 298 employees. |
|||||
| Ransomware | AA Munro Insurance id13479 View details | Canada | Finance / Legal / Insurance | ||
|
AA Munro Insurance - offer personal and commercial insurance solutions, as well as financial services. AA Munro Insurance corporate office is located in 219 Main St Ste 105, Antigonish, Nova Scotia, B2G 2C1, Canada and has 174 employees. |
|||||
| Ransomware | Strauss Brands id13286 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
Strauss Brands (founded in 1937) supplies distributors, restaurants, retailers, and hotels with premium quality, ethically rais ed specialty meats. Products include american grass-fed beef, american lamb, and raised veal. The total amount of data leakage is 264.4 GB |
|||||
| Ransomware | Harry Perkins Institute of medical research id13285 View details | Australia | Healthcare / Pharma | ||
|
The Harry Perkins Institute of medical research is a leading Western Australian medical research centre, dedicated to tackling some of the world’s biggest health issues. Harry Perkins Institute of Medical Research corporate office is located in PO Box 7214, Australia and has 172 employees. 4.6TB of internal building carmera recordings have been uploaded. |
|||||
| Ransomware | Viasat id13284 View details | Spain | Telecommunications | ||
|
Viasat offers telematic solutions for the automobile sector, such as car control or fleet and guarantees recovery in case of theft. Viasat Telematics corporate office is located in 6 Avda. Del Arroyo Del Santo, Madrid, Madrid, 28042, Spain. The total amount of data leakage is 98.9 GB |
|||||
| Ransomware | Olympus Group id13283 View details | United States | Communication / Marketing | ||
|
Olympus Group (founded 1893) - provides services in the field custom printing and sewing industry, specializing in large format digital and dye-sublimation printing. Olympus Group corporate office is located in 9000 W Heather Ave, Milwaukee, Wisconsin, 53224, United States and has 254 employees. The total amount of data leakage is 436.9 GB |
|||||
| Ransomware | Ontario West and Bill Blaney Insurance Brokers id13174 View details | Canada | Finance / Legal / Insurance | ||
|
Ontario West and Bill Blaney Insurance Brokers (founded in 1987) insurance company providing services to Southwestern Ontario. Ontario West Insurance Brokers corporate office is located in 1069 Wellington Rd Ste 208, London, Ontario, N6E 2H6, Canada and has 36 employees. The total amount of data leakage is 109.3 GB |
|||||
| Ransomware | North Coast Petroleum id13173 View details | Australia | Energy | ||
|
North Coast Petroleum (founded 1999) provide reliable and efficient delivery of a range of petroleum and oil products throughout the East Coast of Australia, particularly in regional areas. Operating a fleet of modern vehicles, North Coast Petroleum service commercial, rural and retail customers. North Coast Petroleum corporate office is located in 97 Carrington St, Lismore, New South Wales, 2480, Australia and has 27 employees. The total amount of data leakage is 71.5 GB |
|||||
| Ransomware | Tri-City College Prep High School id13116 View details | United States | Education | ||
|
Tri-City College Prep High School ( established 1999 ) - is a grade 9-12 High School in Prescott, Arizona. The school focuses on academics to prepare their students for college life. Tri-City College Prep High School is located in 5522 Side Rd, Prescott, Arizona, 86301, United States and has 24 employees. The total amount of data leakage is 1,2 GB |
|||||
| Ransomware | Fitzgerald, DePietro & Wojnas CPAs, P.C. id13115 View details | United States | Services | ||
|
Fitzgerald, DePietro & Wojnas CPAs, P.C. is a full service tax, accounting and business consulting firm located in Utica, New York. Fitzgerald, Depietro & Wojnas, Cpa's corporate office is located in 291 Genesee St Ste 3, Utica, New York, 13501, United States and has 19 employees. The total amount of data leakage is 92,5 GB |
|||||
| Ransomware | AJE id13114 View details | Peru | Hospitality / Food & Beverage / Tourism | ||
|
AJE engages in the manufacture, distribution, and sale of alcoholic and nonalcoholic beverages. It was founded in 1988. AJE corporate office is located in 373 Ave Manuel Olguín Santiago De Piso 10 Surco 33, Lima, Lima Province, Peru and has 2,896 employees. The total amount of data leakage is 646,4 GB |
|||||
| Ransomware | Victoria Racing Club id13015 View details | Australia | Public Sector | ||
|
The Victoria Racing Club was founded in 1864, from its foundation in 1864 until 2001, the Victoria Racing Club was the responsible authority for the conduct of thoroughbred racing in the State of Victoria, Australia.Today, the VRC still operates Flemington under a board of directors. More than 30,000 thousand club members enjoy all the benefits of club members. The total amount of data leakage is 128.1 GB |
|||||
| Ransomware | GEMCO Constructors id12990 View details | United States | Public Sector | ||
|
GEMCO Constructors is a mechanical, electrical and plumbing design company. GEMCO Constructors corporate office is located in 6525 Guion Rd, Indianapolis, Indiana, 46268, United States and has 187 employees. The total amount of data leakage is 1.0 TB |
|||||
| Ransomware | Dynamo Electric id12989 View details | Canada | Energy | ||
|
Dynamo Electric is a design-build and technical service oriented company that specializes in power and control solutions. Dynamo Electric corporate office is located in 1383 Fletcher Rd, Saskatoon, Saskatchewan, S7M 5H5, Canada and has 84 employees. The total amount of data leakage is 149.6 GB |
|||||
| Ransomware | Farnell Packaging id12988 View details | Canada | Other | ||
|
Founded in 1961, Farnell Packaging is a family-owned and operated flexible packaging manufacturer servicing the North American market. The companyis headquartered in Dartmouth, Nova Scotia, Canada. The total amount of data leakage is 193.9 GB |
|||||
| Ransomware | Health People id12894 View details | United States | Healthcare / Pharma | ||
|
Health People (established in 1990) is a peer education, prevention and support organization in the South Bronx whose mission is to train and empower residents of communities overwhelmed by chronic disease and AIDS. Health People corporate office is located in 552 Southern Blvd Fl 2, Bronx, New York, 10455, United States and has 48 employees. The total amount of data leakage is 13.1 GB |
|||||
| Ransomware | IPPBX id12893 View details | United States | Services | ||
|
IPPBX - the company is a developer of program solutions, cloud platforms, virtualization systems and so on, offering its services to small and medium -sized businesses. Ippbx corporate office is located in 3500 S Dupont Hwy, Dover, Delaware, 19901, United States and has 57 employees. The total amount of data leakage is 903.5 MB |
|||||
| Ransomware | Market Pioneer International Corp id12892 View details | United States | Transportation / Travel / Logistics | ||
|
Market Pioneer International Corp. was established in 1988 is international freight forwarders in global logistics marketplace, сarrying out the processing and coordination of logistics of international cargoes.Market Pioneer International corporate office is located in 17915 149th Rd, Jamaica, New York, 11434, United States and has 64 employees. The total amount of data leakage is 42.2 GB |
|||||
| Ransomware | Mercy Drive Inc id12891 View details | United States | Services | ||
|
Mercy Drive Inc.'s - provides services to support people with developmental disabilities and intelligence of different age categories. Mercy Drive corporate office is located in 11710 Hillside Ave, Jamaica, New York, 11418, United States and has 203 employees. The total amount of data leakage is 161.1 GB |
|||||
| Ransomware | Radiosurgery New York id12890 View details | United States | Healthcare / Pharma | ||
|
Radiosurgery New York - are one of the leading centers for radiation and radiosurgery worldwide. Radiosurgery New York corporate office is located in 1384 Broadway at 38 Th St, New York City, New York, 10018, United States and has 7 employees. The total amount of data leakage is 64.7 GB |
|||||
| Ransomware | Inside Broadway id12889 View details | United States | Public Sector | ||
|
Inside Broadway - children's theater organization founded in 1982 by Michael Presser. Inside Broadway corporate office is located in 630 9th Ave Ste 802, New York City, New York, 10036, United States and has 17 employees. The total amount of data leakage is 1.3 GB |
|||||
| Ransomware | Oracle Advisory Services id12888 View details | United States | Services | ||
|
Oracle Advisory Services provides financial and management services to hedge funds, private equity firms, & high net-worth individuals. Oracle Advisory Services corporate office is located in 45 W 34th St Ste 911-912, New York City, New York, 10001, United States. The total amount of data leakage is 13.2 GB |
|||||
| Ransomware | Women's Sports Foundation id12887 View details | United States | NGOs / Associations | ||
|
The Women's Sports Foundation (founded in 1974) - the fund provides support to girls and women in sports, implementing and conducting research and various programs.Women's Sports Foundation corporate office is located in 247 W 30th St Fl 5, New York City, New York, 10001, United States and has 105 employees.The total amount of data leakage is 36.5 GB |
|||||
| Ransomware | St. Helena id12795 View details | United States | Public Sector | ||
|
St. Helena (Incorporated March 24, 1876) - is a city in Napa County, California, United States. Located in the North Bay region of the San Francisco Bay Area, the population was 5,438 at the 2020 census. The total amount of data leakage is 120.33 GB |
|||||
| Ransomware | Sems and Specials id12787 View details | United States | Public Sector | ||
|
Sems and Specials (founded in 1990) - manufacturer of various screws, types of washers, head styles, drive styles, materials, as well as other various fastening and connecting elements. Sems and Specials corporate office is located in 6483 Falcon Rd, Rockford, Illinois, 61109, United States. The total amount of data leakage is 122.13 GB |
|||||
| Ransomware | Wichita County Mounted Patrol id12778 View details | United States | Public Sector | ||
|
In 1957 a group of 15 men, under the leadership of Dr. Ted Alexander, organized the Wichita County Sheriff’s Patrol. 10 years later the Sheriff’s Patrol changed its name to the Wichita County Mounted Patrol. Wichita County Mounted Patrol corporate office is located in 2504 Fm-369, Wichita Falls, Texas, 76310, United States. The total amount of data leakage is 1.53 TB and includes lots of interesting critical data. |
|||||
| Ransomware | Brownell Boat Stands & Equipment Company id12777 View details | United States | Public Sector | ||
|
Brownell Boat Stands & Equipment Company ((founded 1954)- manufactures safest boat stands and equipment on the market. Brownell Boat Stands corporate office is located in 5 Boat Rock Rd, Mattapoisett, Massachusetts, 02739, United States. The total amount of data leakage is 17.00 GB |
|||||
| Ransomware | Aztec Services Group id12649 View details | United States | Services | ||
|
Aztec Services Group, Inc - the scope of the company is environmental remediation and demolition services. Aztec Services Group, Inc corporate office is located in 3814 William P Dooley Bypass, Cincinnati, OH 45223, USA. The total amount of data leakage is 398.38 GB |
|||||
| Ransomware | International Modern Hospital id12648 View details | United Arab Emirates | Healthcare / Pharma | ||
|
International Modern Hospital (IMH) (established in 2005) is the oldest private hospital in north Dubai. IMH is a tertiary multi-specialty hospital - the modern facilities include a total of 117 beds (with 4 VIP suites), 5 fully equipped operating theatres plus an endoscopy suite, intensive care facilities, oncology and dialysis wards and rehabilitation & physiotherapy services. International Modern Hospital is located in Sheikh Rashid Rd, Dubai, Dubai, 121735, United Arab Emirates and has 484 employees. The total amount of data leakage is 1.45 TB |
|||||
| Ransomware | Heras id12647 View details | United Kingdom | Services | ||
|
Heras (founded in 1952) is an end-to-end supplier of permanent and mobile perimeterprotection solutions. They design, manufacture, install and service temporary and permanent perimeter protection solutions for customers across business, community and industry sectors. Heras UK corporate office is located in Apex Building 1 Water Vole Way, Doncaster, South Yorkshire, DN4 5JP, United Kingdom and has 6 employees. The total amount of data leakage is 393.14 GB |
|||||
| Ransomware | WEICON id12609 View details | Germany | Communication / Marketing | ||
|
WEICON GmbH & Co. KG (founded in 1947) - produces special adhesives and sealants, technical sprays, highly effective mounting pastes and lubricants for all areas of industry - from production to repair and maintenance, as well as develops, sells and distributes stripping tools. WEICON GmbH & Co. KG corporate office is located in Muenster, Germany. The total amount of data leakage is 175.5 GB |
|||||
| Ransomware | County Connection id12608 View details | United States | Public Sector | ||
|
County Connection was formed in 1980 as a Joint Powers Agency under the legal name The Central Contra Costa Transit Authority. Today County Connection provides fixed-route and paratransit bus service throughout the communities of Concord, Pleasant Hill, Martinez, Walnut Creek, Clayton, Lafayette, Orinda, Moraga, Danville, San Ramon. County Connection corporate office is located in 2477 Arnold Industrial Way, Concord, California, 94520, United States. The total amount of data leakage is 100 GB |
|||||
| Ransomware | Elm Grove id12607 View details | United States | Public Sector | ||
|
Elm Grove is a village in Waukesha County, Wisconsin, United States. The population was 6,524 at the 2020 census. Elm Grove was named as America's best suburb by Business Insider in October 2014. Elm Grove government is headed by a village president and overseen by a board of trustees, the seven members of which are elected to two-year terms. The total amount of data leakage is 150.6 GB |
|||||
| Ransomware | Comwave id12606 View details | Canada | Communication / Marketing | ||
|
Comwave is Canada’s communications company, offering home internet, TV and phone services. Comwave corporate office is located in 61 Wildcat Rd, Toronto, Ontario, M3J 2P5, Canada and has 235 employees. The total amount of data leakage is 274.8 GB |
|||||
| Ransomware | Colonial Surety Company id12579 View details | United States | Communication / Marketing | ||
|
Colonial Surety Company (founded in 1930) is a direct seller and writer of surety bonds, fidelity bonds and insurance products for a wide range of professionals and industries. Colonial Surety Company corporate office is located in 123 Tice Blvd Ste 250, Woodcliff Lake, New Jersey, 07677, United States and has 89 employees. The total amount of data leakage is 143.9 GB |
|||||
| Ransomware | Brick Court Chambers id12506 View details | United Kingdom | Finance / Legal / Insurance | ||
|
Founded in 1921, Brick Court Chambers is one of barristers’ chambers in the UK. Specializes in Commercial, Competition, International/EU and Public Law.Brick Court Chambers corporate office is located in 7-8 Essex St, London, Greater London, WC2R 3LD, United Kingdom. The total amount of data leakage is 140.93 GB |
|||||
| Ransomware | NITEK International LLC id12502 View details | United States | Communication / Marketing | ||
|
NITEK International LLC (founded 1991), a manufacturer of data transmission products, specialized in the research and development of products for the data transmission and security equipment market.NITEK International LLC corporate office is located in729 1st Ave N Birmingham, AL 35203 U.S.A. The total amount of data leakage is 22.13 GB |
|||||
| Ransomware | National Metalwares, L.P id12501 View details | United States | Manufacturing / Engineering | ||
|
National Metalwares, L.P. (founded 1946), is a customer driven, high volume manufacturer, fabricator and finisher of welded steel tubing and tubular components. National Metalwares corporate office is located in 900 N Russell Ave, Aurora, Illinois, 60506, United States and has 40 employees. The total amount of data leakage is 48.19 GB |
|||||
| Ransomware | Merritt Properties, LLC id12386 View details | United States | Communication / Marketing | ||
|
Merritt Properties, LLC develops and manages commercial properties in Maryland. It offers land entitlement and rezoning, site development. Merritt Properties corporate office is located in 2066 Lord Baltimore Dr, Windsor Mill, Maryland, 21244, United States and has 268 employees. The total amount of data leakage is 70.67 GB |
|||||
| Ransomware | Autobell Car Wash, Inc id12385 View details | United States | Public Sector | ||
|
Founded in 1969, Autobell Car Wash, Inc. is a conveyorized car wash company that offers interior and exterior wash options.Autobell Car Wash corporate office is located in 1521 E 3rd St, Charlotte, North Carolina, 28204, United States and has 584 employees.The total amount of data leakage is 183.3 GB |
|||||
| Ransomware | One Toyota of Oakland id12364 View details | United States | Finance / Legal / Insurance | ||
|
One Toyota of Oakland sells new and used Toyota vehicles. One Toyota of Oakland corporate office is located in 8181 Oakport St, Oakland, California, 94621, United States and has 81 employees. The total amount of data leakage is 45.8 GB and include their financial records and customer information. |
|||||
| Ransomware | Chemring Group id12363 View details | United Kingdom | Communication / Marketing | ||
|
Chemring Group is a global business providing a range of advanced technology products and services to the aerospace, defence and security markets. Chemring Group corporate office is located in Roke Manor Old Salisbury Ln, Romsey, Hampshire, SO51 0ZN, United Kingdom and has 393 employees. The total amount of data leakage is 186.78 GB and include confidential documents, databases and solidworks design files. |
|||||
| Ransomware | Patterson & Rothwell Ltd id12293 View details | United Kingdom | Communication / Marketing | ||
|
Patterson & Rothwell Ltd (founded 1982) is a plastic moulder, providing a wide range of product applications for all industries. Patterson & Rothwell Ltd corporate office is located in Bee Works, Shaw Road, Royton, Oldham, OL2 6EH, England. The total amount of data leakage is 22.7 GB |
|||||
| Ransomware | Boyden id12292 View details | United States | Services | ||
|
Boyden (founded 1946) - a consulting firm engaged, among other things, in the search for managers for various areas of business, interim management, and so on. Boyden corporate office is located in 520 White Plains Rd Ste 500, Tarrytown, New York, 10591, United States and has 984 employees. The total amount of data leakage is 79.3 GB |
|||||
| Ransomware | W.F. Whelan id12291 View details | United States | Transportation / Travel / Logistics | ||
|
W.F. Whelan Company (founded 1974) is a full service logistics company. WF Whelan corporate office is located in 41425 Joy Rd, Canton, Michigan, 48187, United States and has 101 employees. The total amount of data leakage is 175.67 GB |
|||||
| Ransomware | Macildowie Associates id12272 View details | United Kingdom | Communication / Marketing | ||
|
Established in 1993, Macildowie is specialising in Human Resources, Accountancy & Finance, Procurement & Supply Chain, Office & Commercial Support and Sales & Marketing recruitment across the Midlands. Macildowie Associates corporate office is located in Waterfront House, Station Street, Nottingham, England, NG2 3DQ The total amount of data leakage is 21.5 GB |
|||||
| Ransomware | Lewis Brothers Bakeries id12238 View details | United States | Public Sector | ||
|
Lewis Brothers Bakeries - a company that operates a chain of bakeries in 17 states. Lewis Brothers Bakeries corporate office is located in 1220 W Michigan St, Evansville, Indiana, 47710, United States and has 396 employees. The total amount of data leakage 115.92 GB |
|||||
| Ransomware | S.A. Piazza & Associates id12237 View details | United States | Public Sector | ||
|
S.A. Piazza & Associates (founded 1967) - major pizza manufacturer and seller. S.A. Piazza & Associates corporate office is located in 15815 SE Piazza Ave, Clackamas, Oregon, 97015, United States and has 53 employees. The total amount of data leakage is 18.63 GB |
|||||
| Ransomware | MyoVision id12236 View details | United States | Healthcare / Pharma | ||
|
MyoVision (founded 1989) - developer and manufacturer of medical equipment for the study of the body. Many of the company's developments are used by NASA. MyoVision corporate office is located in 13545 Erickson Pl NE Ste 200, Seattle, Washington, 98125, United States. The total amount of data leakage is 18.61 GB |
|||||
| Ransomware | Woodfords Family Services id12235 View details | United States | Services | ||
|
Woodfords Family Services was founded in 1967 and its main activity is the support and integration of people with disabilities. Woodfords Family Services corporate office is located in 15 Saunders Way Ste 900, Westbrook, Maine, 04092, United States and has 435 employees. The total amount of data leakage is 198.5 GB |
|||||
| Ransomware | Anders Group id12169 View details | United States | Healthcare / Pharma | ||
|
Anders Group (founded 2010) - is engaged in recruiting specialists for medical institutions throughout the country. Anders Group corporate office is located in 105 Decker Ct Ste 600, Irving, Texas, 75062, United States and has 185 employees. The total amount of data leakage is 214.48 GB |
|||||