Ransomware Group intelligence
Medusa
InactiveTrack Medusa with 521 published victims and 12 known leak locations in a single intelligence view.
Overview
Medusa is tracked by Breach House as a ransomware group with 521 published victims.
United States is currently the most targeted country in this dataset.
12 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (12)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 10 | Onion service | Down checked 2h ago | hupxs7ps7md24kpz4lwsbra64abgxjx3pcc2wuca5ibawf2g5hlpfyqd.onion |
| Leak location 8 | Onion service | Down checked 2h ago | cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion |
| Leak location 6 | Onion service | Down checked 2h ago | s7lmmhlt3iwnwirxvgjidl6omcblvw2rg75txjfduy73kx5brlmiulad.onion |
| Leak location 12 | Onion service | Down checked 2h ago | 7aqabivkwmpvjkyefonf3gpy5gsubopqni7kcirsrq3pflckxq5zz4id.onion |
| Leak location 11 | Onion service | Down checked 2h ago | 62foekhv5humjrfwjdyd2dgextpbf5i7obguhwvfoghmu3nxpkmxlcid.onion |
| Leak location 4 | Onion service | Down checked 2h ago | dlmfciajg5s4vliyo5dhs5jyzhi2xr2fnkebul46lpf4xudtqiue4nid.onion |
| Leak location 7 | Web location | Down checked 2h ago | 45.9.148.39 |
| Leak location 5 | Onion service | Down checked 2h ago | kyfiw76eol6ph2mq7pi5e5tdvce37bicddhai62qhdc5ja6jdchz4qqd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion |
| Leak location 9 | Onion service | Down checked 2h ago | xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion |
| Leak location 2 | Onion service | Down checked 2h ago | medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion |
| Leak location 1 | Onion service | Down checked 2h ago | medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion |
Top Activity Sectors (17)
- Communication / Marketing 105
- Services 55
- Public Sector 54
- Healthcare / Pharma 52
- Education 40
- Finance / Legal / Insurance 32
- Construction / Real Estate 31
- IT 30
- Manufacturing / Engineering 28
- Retail / E-commerce 20
- Hospitality / Food & Beverage / Tourism 17
- Energy 13
- Transportation / Travel / Logistics 13
- Agriculture / Food 9
- NGOs / Associations 7
- Telecommunications 6
- Not identified 4
Typical Attacks (64)
▼How Medusa typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Medusa Group, Medusa Ransomware.
-
T1583.006 Web Services Resource Development
What they do: Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions.
What that means: Adversaries may register for web services that can be used during targeting.
-
T1585.001 Social Media Accounts Resource Development
What they do: Medusa Group has created social media accounts including Telegram and X to publicize their activities.
What that means: Adversaries may create and cultivate social media accounts that can be used during targeting.
-
T1585.002 Email Accounts Resource Development
What they do: Medusa Group has created email accounts used in ransomware negotiations.
What that means: Adversaries may create email accounts that can be used during targeting.
-
T1588.002 Tool Resource Development
What they do: Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
T1608.002 Upload Tool Resource Development
What they do: Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise.
What that means: Adversaries may upload tools to third-party or adversary controlled infrastructure to make it accessible during targeting.
-
T1650 Acquire Access Resource Development
What they do: Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs).
What that means: Adversaries may purchase or otherwise acquire an existing access to a target system or network.
-
What they do: Medusa Group has utilized compromised legitimate local and domain accounts within the victim environment to facilitate remote access and lateral movement sometimes in combination with PsExec.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Medusa Group has leveraged public facing vulnerabilities in their campaigns against victim organizations to gain initial access.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1047 Windows Management Instrumentation Execution
What they do: Medusa Group has utilized Windows Management Instrumentation to query system information.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: Medusa Group has leveraged PowerShell for execution and defense evasion.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Medusa Group has used Windows Command Prompt to control and execute commands on the system to include ingress, network, and filesystem enumeration activities.
What that means: Adversaries may abuse the Windows command shell for execution.
-
What they do: Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy.
What that means: Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network.
-
T1106 Native API Execution
What they do: Medusa Group has leveraged Windows Native API functions to execute payloads.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1559 Inter-Process Communication Execution
What they do: Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication.
What that means: Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution.
-
T1559.001 Component Object Model Execution
What they do: Medusa Group has leveraged Component Object Model (COM) to bypass UAC.
What that means: Adversaries may use the Windows Component Object Model (COM) for local code execution.
-
T1569.002 Service Execution Execution
What they do: Medusa Group has utilized PsExec to execute scripts and commands within victim environments.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Medusa Group has modified Registry keys to elevate privileges, maintain persistence and allow remote access.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1136.002 Domain Account Persistence
What they do: Medusa Group has created a domain account within the victim environment.
What that means: Adversaries may create a domain account to maintain access to victim systems.
-
T1505.003 Web Shell Persistence
What they do: Medusa Group has utilized webshells to an exploited Microsoft Exchange Server.
What that means: Adversaries may backdoor web servers with web shells to establish persistent access to systems.
-
What they do: Medusa Group has used vulnerable or signed drivers to modify security solutions on victim devices.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027.002 Software Packing Stealth
What they do: Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1027.010 Command Obfuscation Stealth
What they do: Medusa Group has obfuscated PowerShell scripts with Base64 encoding.
What that means: Adversaries may obfuscate content during command execution to impede detection.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Medusa Ransomware has utilized XOR encrypted strings.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.003 Clear Command History Stealth
What they do: Medusa Group has cleared command history by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.
What that means: In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.
-
T1070.004 File Deletion Stealth
What they do: Medusa Group has deleted previously installed tools.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1218.014 MMC Stealth
What they do: Medusa Group has leveraged Microsoft Management Console (MMC) to facilitate lateral movement and to interact locally or remotely with victim devices using the command `mmc.exe compmgmt.msc /computer:{hostname/ip}`.
What that means: Adversaries may abuse mmc.exe to proxy execution of malicious .msc files.
-
T1564.003 Hidden Window Stealth
What they do: Medusa Group has utilized the `ShowWindow` API function to hide the current window.
What that means: Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
-
T1679 Selective Exclusion Stealth
What they do: Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device.
What that means: Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution.
-
T1553.002 Code Signing Defense Impairment
What they do: Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools.
What that means: Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1686 Disable or Modify System Firewall Defense Impairment
What they do: Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings.
What that means: Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action.
-
T1690 Prevent Command History Logging Defense Impairment
What they do: Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.
What that means: Adversaries may impair command history logging to hide commands they run on a compromised system.
-
T1003.001 LSASS Memory Credential Access
What they do: Medusa Group has leveraged Mimikatz to dump LSASS to harvest credentials.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1003.003 NTDS Credential Access
What they do: Medusa Group has accessed the ntds.dit file to engage in credential dumping.
What that means: Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights.
-
T1007 System Service Discovery Discovery
What they do: Medusa Ransomware has leveraged an encoded list of services that it designates for termination.
What that means: Adversaries may try to gather information about registered local system services.
-
T1016 System Network Configuration Discovery Discovery
What they do: Medusa Group has obtained host network details utilizing the command `cmd.exe /c ipconfig /all`.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Medusa Group has used PDQ Inventory to get an inventory of the endpoints on the network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1033 System Owner/User Discovery Discovery
What they do: Medusa Group has utilized PsExec to execute `quser` to discover the user session information.
What that means: Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
-
T1046 Network Service Discovery Discovery
What they do: Medusa Group has the capability to use living off the land (LOTL) binaries to perform network enumeration.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1057 Process Discovery Discovery
What they do: Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1069.002 Domain Groups Discovery
What they do: Medusa Group has utilized the `net group` command to query domain groups within the victim environment.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: Medusa Group has leveraged `cmd.exe` to identify system info `cmd.exe /c systeminfo`.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Medusa Group has searched for files within the victim environment for encryption and exfiltration.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.001 Local Account Discovery
What they do: Medusa Group has leveraged `net user` for account discovery.
What that means: Adversaries may attempt to get a listing of local system accounts.
-
T1124 System Time Discovery Discovery
What they do: Medusa Ransomware has discovered device uptime through `GetTickCount()`.
What that means: An adversary may gather the system time and/or time zone settings from a local or remote system.
-
T1135 Network Share Discovery Discovery
What they do: Medusa Group has identified network shares using `cmd.exe /c net share`.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1518.001 Security Software Discovery Discovery
What they do: Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1652 Device Driver Discovery Discovery
What they do: Medusa Group has queried drivers on the victim device through the command `driverquery`.
What that means: Adversaries may attempt to enumerate local device drivers on a victim host.
-
T1680 Local Storage Discovery Discovery
What they do: Medusa Ransomware has enumerated logical drives on infected hosts.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: Medusa Group has used RDP to conduct lateral movement and exfiltrate data.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1071.001 Web Protocols Command and Control
What they do: Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS).
What that means: Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
-
T1090.003 Multi-hop Proxy Command and Control
What they do: Medusa Group has used TOR nodes for communications.
What that means: Adversaries may chain together multiple proxies to disguise the source of malicious traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1219 Remote Access Tools Command and Control
What they do: Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1573.002 Asymmetric Cryptography Command and Control
What they do: Medusa Group has used HTTPS for command and control.
What that means: Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1529 System Shutdown/Reboot Impact
What they do: Medusa Group has manually turned off and encrypted virtual machines.
What that means: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
-
T1657 Financial Theft Impact
What they do: Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (27)
▼Software Medusa has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
!!!READ_ME_MEDUSA!!!.txt
$$\ $$\ $$$$$$$$\ $$$$$$$\ $$\ $$\ $$$$$$\ $$$$$$\ $$$\ $$$ |$$ _____|$$ __$$\ $$ | $$ |$$ __$$\ $$ __$$\ $$$$\ $$$$ |$$ | $$ | $$ |$$ | $$ |$$ / \__|$$ / $$ | $$\$$\$$ $$ |$$$$$\ $$ | $$ |$$ | $$ |\$$$$$$\ $$$$$$$$ | $$ \$$$ $$ |$$ __| $$ | $$ |$$ | $$ | \____$$\ $$ __$$ | $$ |\$ /$$ |$$ | $$ | $$ |$$ | $$ |$$\ $$ |$$ | $$ | $$ | \_/ $$ |$$$$$$$$\ $$$$$$$ |\$$$$$$ |\$$$$$$ |$$ | $$ | \__| \__|\________|\_______/ \______/ \______/ \__| \__| -----------------------------[ Hello, [snip] !!! ]-------------------------- WHAT HAPPEND? ------------------------------------------------------------ 1. We have PENETRATE your network and COPIED data. * We have penetrated entire network including backup system and researched all about your data. * And we have extracted all of your networks including sub offices and your service clients networks valuable data and copied them to private cloud storage. 2. We have ENCRYPTED some your files. While you are reading this message, it means you found your files and data has been ENCRYPTED by world's strongest ransomware. We have access to all of your sub offices and client service networks but didn't lock them all for your brand and privacy. We can solve this issue sliently and smoothly without 3rd parties and we decided lock only some of your main network only. But don't worry, we can restore everything to the original without harming your business. There is only one possible way to get back your systems and business - CONTACT us via LIVE CHAT and pay for the special MEDUSA DECRYPTOR and DECRYPTION KEYs, Data deletion, Keep silent in media. This MEDUSA DECRYPTOR will restore your entire network, This will take less than 1 business day. WHAT GUARANTEES? --------------------------------------------------------------- We can post your data to the public and send emails to your customers. We have professional OSINTs and media team for leak data to telegram, facebook, twitter channels and top news websites. Have a look about us on twitter. You can suffer significant problems due disastrous consequences, leading to loss of valuable intellectual property and other sensitive information, costly incident response efforts, information misuse/abuse, loss of customer trust, brand and reputational damage, legal and regulatory issues. After paying for the data breach and decryption, we guarantee that your data will never be leaked and this is also for our reputation. YOU should be AWARE! --------------------------------------------------------------- If you're not in main chile office, inform your supervisors and stay calm! We will speak only with an authorized person. It can be the CEO, top management, etc. In case you are not such a person - DON'T CONTACT US! Your decisions and action can result in serious harm to your company! If you do not contact us within 3 days, We will start publish your case to our official blog and everybody will start notice your incident! If you do not contact us within 5 days, We will start publish your case and leak video on all social channels and send emails to your customers! --------------------[ Official blog tor address ]-------------------- Using TOR Browser(https://www.torproject.org/download/): http://medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion/ CONTACT US! ----------------------[ Your company live chat address ]--------------------------- Using TOR Browser(https://www.torproject.org/download/): http://medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion/[snip] Or Use Tox Chat Program(https://qtox.github.io/) Add user with our tox ID and wait 24h : 4AE245548F2A225882951FB14E9BF87EE01A0C10AE159B99D1EA62620D91A372205227254A9F Our support email: ( [email protected] ) Company identification hash: [snip]
!!!READ_ME_MEDUSA!!!_2.txt
$$\ $$\ $$$$$$$$\ $$$$$$$\ $$\ $$\ $$$$$$\ $$$$$$\ $$$\ $$$ |$$ _____|$$ __$$\ $$ | $$ |$$ __$$\ $$ __$$\ $$$$\ $$$$ |$$ | $$ | $$ |$$ | $$ |$$ / \__|$$ / $$ | $$\$$\$$ $$ |$$$$$\ $$ | $$ |$$ | $$ |\$$$$$$\ $$$$$$$$ | $$ \$$$ $$ |$$ __| $$ | $$ |$$ | $$ | \____$$\ $$ __$$ | $$ |\$ /$$ |$$ | $$ | $$ |$$ | $$ |$$\ $$ |$$ | $$ | $$ | \_/ $$ |$$$$$$$$\ $$$$$$$ |\$$$$$$ |\$$$$$$ |$$ | $$ | \__| \__|\________|\_______/ \______/ \______/ \__| \__| -----------------------------[ Hello, [snip] !!! ]-------------------------- Sorry to interrupt your busy business. WHAT HAPPEND? ------------------------------------------------------------ 1. We have PENETRATE your network and COPIED data. We have penetrated your entire network and researched all about your data. And we have copied all of your confidential data and uploaded to private storage. * You're running a highly valued business and your data was very crucial. 2. We have ENCRYPTED your files. While you are reading this message, it means your files and data has been ENCRYPTED by world's strongest ransomware. Your files have encrypted with new military-grade encryption algorithm and you can not decrypt your files. But don't worry, we can decrypt your files. There is only one possible way to get back your computers and servers, keep your privacy safe - CONTACT us via LIVE CHAT and pay for the special MEDUSA DECRYPTOR and DECRYPTION KEYs. This MEDUSA DECRYPTOR will restore your entire network within less than 1 business day. WHAT GUARANTEES? --------------------------------------------------------------- We can post all of your critial data to the public and send emails to your competitors. We have professional OSINTs and media team for leak data to telegram, facebook, twitter channels and top news websites. You can easily search about us. You can suffer significant problems due to disastrous consequences, leading to loss of valuable intellectual property and other sensitive information, costly incident response efforts, information misuse/abuse, loss of customer trust, brand and reputational damage, and legal and regulatory issues. After paying for the data breach and decryption, we guarantee that your data will never be leaked and make everything silent, this is also for our reputation. YOU should be AWARE! --------------------------------------------------------------- We will speak only with an authorized person. It can be the CEO, top management etc. In case you ar not such a person - DON'T CONTACT US! Your decisions and action can result in serious harm to your company! Inform your supervisors and stay calm! If you do not contact us within 48 hours, We will start publish your case to our official blog and everybody will start notice your incident! --------------------[ Telegram channel ]-------------------- https://t.me/+yXOcSjVjI9tjM2E0 --------------------[ Official blog tor address ]-------------------- Using TOR Browser(https://www.torproject.org/download/): http://xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion/ http://cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion/ CONTACT US! ----------------------[ Your company live chat address ]--------------------------- Using TOR Browser(https://www.torproject.org/download/): http://uyku4o2yg34ekvjtszg6gu7cvjzm6hyszhtu7c55iyuzhpr4k5knewyd.onion/[snip] Backup Mirrors: http://5ar4vuckm3k7osdlzskqkaqmqr4jjpmdikuotmlpkrbsxx7ard3xetyd.onion/[snip] --------------------[ Or Use Tox Chat Program(https://utox.org/uTox_win64.exe) ]-------------------- Add user with our tox ID : 061AA6BDE8F6DE6C92F0D6E077359BF6911FCAF80030E82B3A3DB65E63C8011343D34F956FEC Our support email: ( [email protected] ) Company identification hash: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (521)
Search, filter and paginate the victim timeline for Medusa. Showing 301–400 of 521.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | The Council of Fashion Designers of America id12128 View details | United States | Public Sector | ||
|
The Council of Fashion Designers of America, Inc, (CFDA) is a not-for-profit trade association founded in 1962 that leads industry-wide initiatives and whose membership consists of more than 400 of America’s foremost womenswear, menswear, jewelry, and accessory designers. The Council of Fashion Designers of America corporate office is located in 1350 Avenue of the Americas Fl 2, New York City, New York, 10019, United States and has 120 employees. The total amount of data leakage is 423.3 GB |
|||||
| Ransomware | Principle Cleaning Services id12127 View details | United Kingdom | Communication / Marketing | ||
|
Principle Cleaning Services founded in 1989 and headquartered in London, offers corporate and commercial cleaning services. Principle Cleaning corporate office is located in 1-9 Romford Rd, London, Greater London, E15 4LJ, United Kingdom and has 7 employees. The total amount of data leakage is 220.58 GB |
|||||
| Ransomware | Ted Brown Music id12081 View details | United States | Retail / E-commerce | ||
|
Ted Brown Music is a family-owned full-service music store established in 1931. Ted Brown Music corporate office is located in 6228 Tacoma Mall Blvd, Tacoma, Washington, 98409, United States and has 95 employees. The total amount of data leakage is 29.4 GB |
|||||
| Ransomware | NORTHEAST OHIO NEIGHBORHOOD HEALTH SERVICES (NEON) id12078 View details | United States | Healthcare / Pharma | ||
|
NORTHEAST OHIO NEIGHBORHOOD HEALTH SERVICES (NEON, founded 1967) is a Federally Qualified Health Center (FQHC) network of community health centers dedicated to improving access to health care. Neon Health Services corporate office is located in 8300 Hough Ave Ste 308, Cleveland, Ohio, 44103, United States and has 138 employees. The total amount of data leakage is 50.96 GB |
|||||
| Ransomware | Lee University id11706 View details | United States | Education | ||
|
Lee University is a private, comprehensive university that was founded in 1918 in Cleveland, Tennessee. The number of students enrolled is more than 4,000 people. Lee University corporate office is located in 1120 N Ocoee St, Cleveland, Tennessee, 37311, United States and has 1,223 employees. The total amount of data leakage is 387.49 GB |
|||||
| Ransomware | Thermodyn Corporation id11687 View details | United States | Manufacturing / Engineering | ||
|
Thermodyn Corporation (founded 1979) is a coated fabrics and expansion joint manufacturing. Thermodyn specializes in Viton Fluoroelastomer based technologies for gasket fabrication, expansion joints, Fluorodyn caulk & adhesives, and various elastomeric coated substrates. Thermodyn corporate office is located in 3550 Silica Rd, Sylvania, Ohio, 43560, United States and has 22 employees. The total amount of data leakage is 16.70 GB |
|||||
| Ransomware | Traverse City Area Public Schools id11655 View details | United States | Public Sector | ||
|
Traverse City Area Public Schools is a public school district based in Traverse City, Michigan, United States. This district includes 10 elementary schools, 2 middle schools, 2 high schools, 1 alternative high school, and 1 Montessori school. The district serves 8,908 students. Traverse City Area Public Schools school district office is located in 412 Webster St Rm C, Traverse City, Michigan, 49686, United States and has 932 employees. The total amount of data leakage is 1.2 TB |
|||||
| Ransomware | Williams County Abstract Company id11651 View details | United States | Public Sector | ||
|
Williams County Abstract Company (founded 1907) provides services to help you buy or sell residential and commercial property, and also real estate closing, escrow and settlement services and title insurance. Williams County Abstract corporate office is located in 123 E Broadway, Williston, North Dakota, 58801, United States and has 13 employees. The total amount of data leakage is 51.11 GB. |
|||||
| Ransomware | Solano County Library id11650 View details | United States | Public Sector | ||
|
The Solano County Library is a public library system serving the cities of Dixon, Fairfield, Rio Vista, Suisun City, Vacaville and Vallejo, California. The Solano County Library was established in 1914 by the county's board of supervisors. Solano County Library corporate office is located in 601 Pintail Dr 763, Suisun City, California, 94585, United States and has 67 employees. The total amount of data leakage is 85.02 GB |
|||||
| Ransomware | Alliance Mercantile id11649 View details | Canada | Communication / Marketing | ||
|
Alliance Mercantile (founded 1984) - manufacturer and distributor of work clothes, shoes, and cleaning and care products. Alliance Mercantile corporate office is located in 3451 Wayburne Dr, Burnaby, British Columbia, V5G 3L1, Canada and has 104 employees. The total amount of data leakage is 89.25 GB |
|||||
| Ransomware | Novus International id11648 View details | United States | Agriculture / Food | ||
|
Founded in 1991, Novus International creates animal nutrition solutions for livestock, poultry, and aquaculture. Novus International corporate office is located in 20 Research Park Dr, Saint Charles, Missouri, 63304, United States and has 871 employees. The total amount of data leakage is 151.3 GB |
|||||
| Ransomware | John R. Wood Properties id11556 View details | United States | Communication / Marketing | ||
|
Founded in 1958, John R. Wood Properties is a global real estate company headquartered in Naples, FL. John R. Wood Properties corporate office is located in 9130 Corsea Del Fontana Way, Naples, Florida, 34109, United States and has 1,242 employees. The total amount of data leakage is 1.07 TB |
|||||
| Ransomware | Paducah Dermatology id11551 View details | United States | Healthcare / Pharma | ||
|
Paducah Dermatology is a hospital & health care company. Paducah Dermatology corporate office is located in 3101 Parisa Dr Ste 402, Paducah, Kentucky, 42003, United States and has 19 employees. The total amount of data leakage is 15.04 GB |
|||||
| Ransomware | Domestic Violence Project, Inc id11550 View details | United States | Communication / Marketing | ||
|
Domestic Violence Project, Inc. helps victims of domestic violence become survivors by providing emergency, clinical, and supportive services; and promotes increased public awareness of domestic violence issues. Domestic Violence Project corporate office is located in PO Box 9459, Canton, Ohio, 44711, United States and has 15 employees. The total amount of data leakage is 31.2 |
|||||
| Ransomware | Rairdon Automotive Group id11549 View details | United States | Manufacturing / Engineering | ||
|
Rairdon Automotive Group is a locally owned automotive group with 12 dealerships in the Pacific Northwest Honda of Sumner, Honda of Burien, Nissan of Auburn, Subaru of Auburn, Dodge Chrysler Jeep of Marysville/Monroe/Bellingham/Kirkland, Maserati of Kirkland, Alfa Romeo of Kirkland, Volkswagen of Everett, and FIAT of Kirkland. Rairdon Automotive Group corporate office is located in 16302 Auto Ln, Sumner, Washington, 98390, United States and has 152 employees. The total amount of data leakage is 98.5 GB |
|||||
| Ransomware | Integration International id11548 View details | United States | Services | ||
|
Integration International is a digital transformation solutions organization, services range from IT consulting, IT infrastructure, and workforce solutions to application services and AI consulting. Integration International Inc corporate office is located in 1081 Parsippany Blvd, Parsippany, New Jersey, 07054, United States and has 178 employees. The total amount of data leakage is 133.40 GB. Sql databases and software source codes are included in the data leak. |
|||||
| Ransomware | Tarrant Appraisal District id11547 View details | United States | Communication / Marketing | ||
|
Tarrant Appraisal District (TAD) is a political subdivision of the State of Texas created effective January 1, 1980. The provisions of the Texas Property Tax Code govern the legal, statutory, and administrative requirements of the appraisal district. Tarrant Appraisal District corporate office is located in 2500 Handley Ederville Rd, Fort Worth, Texas, 76118, United States and has 237 employees. The total amount of data leakage is 217.79 GB |
|||||
| Ransomware | Orientrose Contracts id11515 View details | United Kingdom | Construction / Real Estate | ||
|
Orientrose Contracts (founded 2004) are a specialist building contractor to the leisure and commercial sector, working with clients in the pub, restaurant, hotel & club sector. Orientrose Contracts corporate office is located in 6 Vantage Park Washingley Rd Unit, Huntingdon, United Kingdom and has 11 employees. The total amount of data leakage is 230.0 GB |
|||||
| Ransomware | Sutton Dental Arts id11514 View details | United States | Healthcare / Pharma | ||
|
Sutton Dental Arts - a dental clinic providing a full range of dental services. Sutton Dental Arts corporate office is located in 1729 W Harvard Ave Ste 5, Roseburg, Oregon, 97471, United States and has 3 employees. The total amount of data leakage is 20.2 GB |
|||||
| Ransomware | San Pasqual Band of Mission Indians id11495 View details | United States | Public Sector | ||
|
The San Pasqual Band of Mission Indians is a federally recognized tribe of the Kumeyaay Indian Nation. They are based in Valley Center, California. San Pasqual Band of Mission Indians office is located in 16400 Kumeyaay Way, Valley Center, California, 92082, United States and has 101 employees. The total amount of data leakage is 134.4 GB |
|||||
| Ransomware | East Baton Rouge Sheriff's Office id11494 View details | United States | Finance / Legal / Insurance | ||
|
East Baton Rouge Sheriff's Office - led by Sheriff Sid Gautreaux, this Office is responsible for enforcing the laws of Louisiana within East Baton Rouge Parish,as well as maintaining the East Baton Rouge Parish Prison. East Baton Rouge Sheriff's Office corporate office is located in 100 Saint Ferdinand St Rm 203, Baton Rouge, Louisiana, 70802, United States and has 510 employees. The total amount of data leakage is 92.2 GB |
|||||
| Ransomware | Williams County Abstract Company id11458 View details | United States | Public Sector | ||
|
Williams County Abstract Company (founded 1907) provides services to help you buy or sell residential and commercial property, and also real estate closing, escrow and settlement services and title insurance. Williams County Abstract corporate office is located in 123 E Broadway, Williston, North Dakota, 58801, United States and has 13 employees. The total amount of data leakage is 51.11 GB |
|||||
| Ransomware | PT Bank Pembangunan Daerah Banten Tbk id11427 View details | Indonesia | Finance / Legal / Insurance | ||
|
PT Bank Pembangunan Daerah Banten Tbk - founded in 1992, it is currently owned by the Banten Provincial government and has the status of a regional development bank. Currently, the Company serves customers of deposits, credit distribution (MSME, Consumer Credit and Commercial Credit), and other services and has been appointed as a partner of the Provincial Government of Banten in local cash management. Bank Pembangunan Daerah Banten Tbk PT corporate office is located in Environment Ruko Nine No. 8b-9a Sumur Pecung Village Jl. Sudirman Kemang, Serang, Banten, Indonesia and has 435 employees. The total amount of data leakage is 108.47 GB and includes all customer financial information SQL Database. |
|||||
| Ransomware | Regina Dental Group id11345 View details | United States | Healthcare / Pharma | ||
|
Regina Dental Group a group of dental offices located at Normanview Crossing, Grasslands Dental and Southland Mall. Regina Dental Group corporate office is located in 398 Mccarthy Blvd, Regina, Saskatchewan, S4R 6A7, Canada and has 10 employees. |
|||||
| Ransomware | Impac Mortgage Holdings id11344 View details | United States | Transportation / Travel / Logistics | ||
|
Impac Mortgage Holdings, founded in 1995 and located in Irvine, California, provides mortgage lending, warehouse lending solutions. Impac Mortgage Holdings corporate office is located in 19500 Jamboree Rd, Irvine, California, 92612, United States and has 672 employees. The amount of data leakage is 592,2 GB. |
|||||
| Ransomware | Henry County, Illinois id11329 View details | United States | Public Sector | ||
|
Henry County, Illinois is located in Northwestern Illinois, just 16 miles from the Mississippi River dividing Illinois and Iowa. Henry County's population in 2000 was 51,020, with the county covering 823.21 square miles. Henry County, Illinois office is located in 307 W Center St Rm 198, Cambridge, Illinois, 61238, United States and has 185 employees. |
|||||
| Ransomware | Suburban Surgical Care Specialists id11294 View details | United States | Public Sector | ||
|
Suburban Surgical Care Specialists - a medical center specializing in all types of surgical intervention. Suburban Surgical Care Specialists corporate office is located in 4885 Hoffman Blvd Ste 400, Hoffman Estates, Illinois, 60192, United States and has 45 employees. |
|||||
| Ransomware | Accipiter Capital Management, LLC id11284 View details | United States | Services | ||
|
Accipiter Capital Management, LLC is a large advisory firm based in Palm Beach Gardens. It manages $119.36 million of regulatory assets for 1 client accounts. It has been registered with the SEC as an adviser since 2012 and has operated in the jurisdictions of Florida, New Jersey, and New York. |
|||||
| Ransomware | Urban Strategies id11283 View details | United States | Communication / Marketing | ||
|
Urban Strategies is a social enterprise that delivers transformational outcomes in hard to reach communities. Urban Strategies corporate office is located in 1918 W Van Buren St Bldg G, Phoenix, Arizona, 85009, United States and has 55 employees. |
|||||
| Ransomware | Romark Laboratories id11264 View details | United States | Healthcare / Pharma | ||
|
Romark Laboratories was founded in 1993, engaged in the development and supply of new innovative medicines. Romark Laboratories L.C corporate office is located in 3000 Bayport Dr Ste 200, Tampa, Florida, 33607, United States and has 124 employees. |
|||||
| Ransomware | Autorità di Sistema Portuale del Mar Tirreno Settentrionale It id11258 View details | Italy | Public Sector | ||
|
Autorità di Sistema Portuale del Mar Tirreno Settentrionale it is a non-economic state body that exclusively manages the territories and assets of maritime state property under its jurisdiction. The office is located at: Scali Rosciano 6/7 57123 Livorno Italy |
|||||
| Ransomware | Elior UK id11257 View details | United Kingdom | Hospitality / Food & Beverage / Tourism | ||
|
Elior UK is a contract catering company providing services to sectors such as care and retirement living, government and workplaces. Elior UK corporate office is located in 1 Crown Cheapside Ct, London, Greater London, EC2V 6JP, United Kingdom and has 7 employees. |
|||||
| Ransomware | Desco Steel id11252 View details | United States | Manufacturing / Engineering | ||
|
Desco Steel was incorporated in 1991, selling a wide variety of structural steel products. Desco Steel corporate office is located in 270 Lancaster Ave Ste G2, Malvern, Pennsylvania, 19355, United States and has 10 employees. |
|||||
| Ransomware | Metzger Veterinary Services id11251 View details | Canada | Healthcare / Pharma | ||
|
Metzger Veterinary Services is a veterinary practice serving the livestock industry in Southern Ontario, specializing in animal health management and the production of beef cattle and pig farming.Metzger Veterinary Services corporate office is located in 5200 Ament Line, Linwood, Ontario, N0B 2A0, Canada and has 29 employees |
|||||
| Ransomware | Kenneth Young Center id11199 View details | United States | Communication / Marketing | ||
|
Kenneth Young Center is a community-based non-profit, comprehensive provider of mental health and senior citizens' support services. Kenneth Young Center corporate office is located in 1001 Rohlwing Rd, Elk Grove Village, Illinois, 60007, United States and has 200 employees. |
|||||
| Ransomware | Denninger’s id11141 View details | United States | Manufacturing / Engineering | ||
|
Denninger’s - the food company that owns: 5 retail locations, a manufacturing plant and a warehouse. Denningers corporate office is located in 826 Queenston Rd, Stoney Creek, Ontario, L8G 4A8, Canada and has 76 employees. |
|||||
| Ransomware | Haivision MCS id11123 View details | United States | Public Sector | ||
|
Haivision MCS (CineMassive until 2022)focuses on providing highly specialized systems designed to address mission-critical challenges in global security operations centers, joint and tactical operations centers, public safety operations centers, and control rooms. Global Headquarters - 150 Ottley Drive NE Atlanta, GA 30324 United States |
|||||
| Ransomware | Tocci Building Corporation id11122 View details | United States | Construction / Real Estate | ||
|
Tocci Building Corporation, founded in 1985, is one of the construction management firms in New England. Tocci Building corporate office is located in 660 Main St 660, Woburn, Massachusetts, 01801, United States and has 126 employees. |
|||||
| Ransomware | JVCKENWOOD id11121 View details | Thailand | Communication / Marketing | ||
|
JVCKENWOOD (Thailand) Co., Ltd. is an overseas subsidiary of JVCKENWOOD Corporation based in Thailand, specialising in being a sole distributor of Kenwood audio products, marketing of JVC audio and video products. JVCKENWOOD (Thailand) Co. corporate office is located 240/33, 240/35 Ayothaya Tower, 18th Floor, Ratchadapisek Soi 18 Road, Huaykwang Bangkok, Bangkok, 10310, Thailand |
|||||
| Ransomware | American Renal Associates id11120 View details | United States | Healthcare / Pharma | ||
|
American Renal Associates (part of the Innovative Renal Care (IRC) group of companies) founded in 1999, it provides high-quality care to patients suffering from end-stage kidney disease (ESRD) and other kidney diseases. American Renal Associates corporate office is located in 500 Cummings Ctr Ste 6550, Beverly, Massachusetts, 01915, United States and has 2,127 employees. |
|||||
| Ransomware | US #1364 Federal Credit Union id11119 View details | United States | Finance / Legal / Insurance | ||
|
US #1364 Federal Credit Union, founded in 1936, is a local credit union with 5 branches in northwest Indiana. Federal Credit Union corporate office is located in 8400 Broadway, Merrillville, Indiana, 46410, United States and has 73 employees. |
|||||
| Ransomware | Paul Davis Restoration id11097 View details | United States | Construction / Real Estate | ||
|
Paul Davis Restoration - founded in 1966, the company currently operates throughout North America (including franchises) and specializes in disaster recovery, restoration and reconstruction.. Paul Davis Restoration corporate office is located in 21 Harvey St, Kingston, Ontario, K7K 5C1, Canada and has 467 employees. |
|||||
| Ransomware | Veeco id11096 View details | United States | Manufacturing / Engineering | ||
|
Veeco is a company that operates in the machinery industry. It employs 11-20 people and has $5M-$10M of revenue. The company is headquartered in Riverside, California. |
|||||
| Ransomware | Prompt Financial Solutions id11088 View details | Canada | Communication / Marketing | ||
|
Prompt Financial Solutions - provides mortgage agents with the opportunity to access loans and mortgages for responsible homeowners. Prompt Financial Solutions corporate office is located in 5420 N Service Rd Ste 205, Burlington, Ontario, L7L 6C7, Canada and has 26 employees. |
|||||
| Ransomware | Sophiahemmet University id11087 View details | Sweden | Education | ||
|
Sophiahemmet University - an academic university offering high-quality education and research in close cooperation with the Sophiahemmet Hospital since 1884. Located at Stockholm, Södermanland, 11486, SE |
|||||
| Ransomware | Centennial Law Group LLP id11086 View details | Canada | Finance / Legal / Insurance | ||
|
Centennial Law Group LLP is a law firm engaged in providing legal services to both private and corporate clients. Centennial Law Group corporate office is located in 25 Main St W Ste 1702, Hamilton, Ontario, L8P 1H1, Canada and has 17 employees. |
|||||
| Ransomware | Eastern Rio Blanco Metropolitan id11085 View details | United States | Public Sector | ||
|
Eastern Rio Blanco Metropolitan (ERBM) Recreation & Park District is a special district in Rio Blanco County, Colorado that was founded in 1981,in 2008, Meeker Recreation Center was created on its basis. |
|||||
| Ransomware | Chris Argiropoulos Professional id11084 View details | Canada | Communication / Marketing | ||
|
Chris Argiropoulos Professional - a law firm specializing in both corporate and private clients. Chris Argiropoulos Professional corporate office is located in 100 George St, Hamilton, Ontario, L8P 1E2, Canada and has 4 employees. |
|||||
| Ransomware | Stoney Creek Furniture id11077 View details | Canada | Retail / E-commerce | ||
|
Stoney Creek Furniture, founded in 1969, is a large furniture store offering any furniture, including custom-made furniture. Stoney Creek Furniture corporate office is located in 395 Lewis Rd, Stoney Creek, Ontario, L8E 5N5, Canada and has 72 employees. |
|||||
| Ransomware | JS International id10999 View details | United States | Retail / E-commerce | ||
|
JS International, Inc. was founded in 1997 and is engaged in the manufacture of solid wood furniture structures (cabinets, accessories, etc.). The company currently has 95 employees. JSI Cabinetry corporate office is located in 485 Commerce Dr, Fall River, Massachusetts, 02720, United States |
|||||
| Ransomware | Penn Cinema id10985 View details | United States | Transportation / Travel / Logistics | ||
|
Penn Cinema was founded in 2006 as a family-owned and independent cinema and currently operates a chain of 30 cinemas. Penn Cinema corporate office is located in 30 P Pm Lititz Pa 541 Airport Rd, Lititz, Pennsylvania, 17543, United States. |
|||||
| Ransomware | Southwest Industrial Sales id10980 View details | United States | Manufacturing / Engineering | ||
|
Southwest Industrial Sales, founded in 2008, manufactures precision components, products and assemblies, as well as provides services specializing in automation of the manufacturing and processing industries, precision manufacturing for various industries. SW Industrial Sales corporate office is located in 4012 W Lindbergh Way, Chandler, Arizona, 85226, United States and has 10 employees. |
|||||
| Ransomware | The Professional Liability Fund id10979 View details | United States | Communication / Marketing | ||
|
The Professional Liability Fund (PLC) was established in 1977 in accordance with state law (ORS 9.080) and with the approval of OSB members. PLF began its operations on July 1, 1978 and since that date has been a mandatory provider of primary negligence insurance for lawyers (more than 7,000 people) in the state of Oregon, the only U.S. state in which such insurance is mandatory. Professional Liability Fund corporate office is located in 16037 SW Upper Boones Ferry Rd Ste 300, Portland, Oregon, 97224, United States and has 68 employees. |
|||||
| Ransomware | Acorn id10946 View details | United Kingdom | Construction / Real Estate | ||
|
Acorn, founded in 1995, is an independent property development and investment company and a significant player in the UK property market. Acorn Property Group corporate office is located in 28 Headland Rd, Newquay, Cornwall, TR7 1HN, United Kingdom and has 4 employees. |
|||||
| Ransomware | Pressco Technology id10945 View details | United States | IT | ||
|
Pressco Technology, founded in 1966 and headquartered in Cleveland, Ohio, is a manufacturer of equipment that specializes in inspection manufacturing process. Pressco Technology corporate office is located in 29200 Aurora Rd, Cleveland, Ohio, 44139, United States and has 212 employees. |
|||||
| Ransomware | Bimbo Bakeries id10899 View details | Mexico | IT | ||
|
Grupo Bimbo was founded in 1945. In 2002, the group was restructured and all companies were divided into four divisions: 1) Bimbo, S.A. unites the baking industry of Mexico and Central America; 2) Barcel, S.A. includes offices and sales in Botanas (small savory snacks) and Ricolino (chocolate); 3) Bimbo Bakeries USA (BBU) serves the US market; 4) Bimbo Canada serves the Canadian market 5) Organization Latinoamericana (OLA) serves the South American market. Grupo Bimbo has 105 enterprises in 18 countries in America, Europe and Asia. Their network is technically supported by DXC Technology, and network configuration was poor and vulnerable. |
|||||
| Ransomware | The Chas. E. Phipps id10884 View details | United States | Construction / Real Estate | ||
|
The Chas. E. Phipps - the company was founded in 1921, and currently employs 67 employees. The company supplies concrete accessories, concrete repair materials, sealants, coatings and various building materials to contractors. The Chas E Phipps corporate office is located in 4560 Willow Pkwy, Cleveland, Ohio, 44125, United States. |
|||||
| Ransomware | Modern Kitchens id10794 View details | United States | Public Sector | ||
|
Modern Kitchens is a distributor of built-in appliances and cabinets in upstate New York. The corporate office is located at 5801 Court Street Rd. At Military Cir, Syracuse, New York 13206, US |
|||||
| Ransomware | Kadac Australia id10770 View details | Australia | Healthcare / Pharma | ||
|
Founded in 1973, Kadac is a supplier of organic, natural and health products serving the Asia-Pacific region. Kadac corporate office is located in 151-155 Woodlands Dr, Braeside, Victoria, 3195, Australia |
|||||
| Ransomware | Amoskeag Network Consulting Group LLC id10768 View details | United States | Services | ||
|
Amoskeag Network Consulting Group, LLC is a provider of IT outsourcing, virtualization and cloud services, the company was founded more than 30 years ago and employs 13 employees. Amoskeag Network Consulting Group corporate office is located in 75 Gilcreast Rd Unit 306, Londonderry, New Hampshire, 03053, United States |
|||||
| Ransomware | ArpuPlus id10696 View details | Egypt | IT | ||
|
ArpuPlus is a subsidiary of A15 (a digital product and technology brand company) founded in 2003, headquartered in Cairo, Egypt, providing a wide range of services in the field of mobile value-added services (VAS) and platform solutions. |
|||||
| Ransomware | Digitel Venezuela id10656 View details | Venezuela, Bolivarian Republic of | Telecommunications | ||
|
Digitel is a mobile phone company in Venezuela founded in 1995. The number of subscribers of the company is more than 5,000,000, and the number of employees is more than 1,100 people. Digitel corporate office is located in Edificio El Cubo Negro Tor Banaven Cl. Ln Piso 8, Caracas, Capital, Venezuela |
|||||
| Ransomware | Galaxy Fireworks, Inc id10629 View details | United States | Retail / E-commerce | ||
|
Galaxy Fireworks, Inc. - importer, wholesaler and retailer of fireworks. The company was founded in 1984 and has 26 employees. Galaxy Fireworks corporate office is located in 204 E Dr Martin Luther King Jr Blvd, Tampa, Florida, 33603, United States |
|||||
| Ransomware | Kansas City Area Transportation Authority id10587 View details | United States | Public Sector | ||
|
Founded in 1969 The Kansas City Area Transportation Authority is a public transportation agency serving counties in the Kansas City Area and has 327 employees.Kansas City Area Transportation Authority corporate office is located in 1200 E 18th St, Kansas City, Missouri, 64108, United States. |
|||||
| Ransomware | CloudFire Italy id10571 View details | Italy | IT | ||
|
CloudFire - an Italian Service Cloud Platform. The company was founded in 2017, has 23 employees, and its corporate office is located at Via Giambattista Vico 93, 42124 – Reggio Emilia |
|||||
| Ransomware | Signature Performance Insurance id10544 View details | United States | Finance / Legal / Insurance | ||
|
Signature Performance (Signature) is a leading provider of healthcare administrative solutions and services. The company was created in 2004, at present the staff of the arts are more than 1250 people. Signature Performance corporate office is located in 10250 Regency Cir Ste 500, Omaha, Nebraska, 68114, United States |
|||||
| Ransomware | Waldner's id10506 View details | United States | Public Sector | ||
|
Waldner's, founded in 1939, is an office furniture company. They offer a variety of products including chairs, open plan workstations, tables and more. Waldner's corporate office is located in 215 Lexington Ave, New York City, New York, 10016, United States |
|||||
| Ransomware | Pozzi Italy id10505 View details | Italy | Hospitality / Food & Beverage / Tourism | ||
|
Pozzi Leopoldo Srl is a company that operates in the machinery industry. It employs 11-20 people and has $1M-$5M of revenue. The company is headquartered in Barlassina, Lombardia, Italy |
|||||
| Ransomware | The Gainsborough Bath id10504 View details | United Kingdom | Services | ||
|
The Gainsborough Bath Spa offers a variety of meeting and banqueting facilities suitable for events and business meetings. The Gainsborough Bath Spa corporate office is located in Beau Street, Bath BA1 1QY, England |
|||||
| Ransomware | Richmond Fellowship Scotland id10503 View details | United Kingdom | Communication / Marketing | ||
|
Richmond Fellowship Scotland is a charity that serves over 2,000 people and is the largest social care provider in Scotland. The Richmond Fellowship Scotland corporate office is located in 3 Buchanan Gate Buchanan Gate Business Park Cumbernauld Rd, Stepps, North Lanarkshire, G33 6FB, United Kingdom |
|||||
| Ransomware | Stone, Avant & Daniels id10449 View details | United States | Communication / Marketing | ||
|
Stone, Avant & Daniels — the company provides accounting and taxation services in the Birmingham area. The main office of the company is located at 625 Springdale Rd, Birmingham, Alabama 35217, US |
|||||
| Ransomware | Limburg id10393 View details | Belgium | Public Sector | ||
|
Limburg.net - It is an inter-municipal waste company of Limburg and Liszt. Provides waste collection in 44 municipalities of the province of Limburg and the city of Dist. The main office of the company is located at 32 Gouverneur Verwilghensingel, Hasselt, Flanders, 3500, Belgium |
|||||
| Ransomware | Water For People id10392 View details | United States | Communication / Marketing | ||
|
Water For People is a global nonprofit dedicated to promoting the development of high-quality drinking water and sanitation services, accessible to all, and sustained by strong communities, businesses and governments. The main office of the company is located at 100 E Tennessee Ave, Denver, Colorado, 80209, United States. |
|||||
| Ransomware | ATCO Products Inc id10060 View details | United States | Communication / Marketing | ||
|
ATCO Products Inc. designs, manufactures, and supplies automotive air conditioning components for original equipment suppliers and aftermarket customers. The companys product categories include accumulators and driers, hose assemblies, crimpers and tools.The main office of the company is located at Interstate Hwy 45, Ferris, Texas, 75125, United States |
|||||
| Ransomware | Biomatrix LLC id10059 View details | United States | Healthcare / Pharma | ||
|
Founded in 1997, Biomatrix LLC specializes in biomedical and clinical research services. The company is based in Plantation, Florida, 33324, United States |
|||||
| Ransomware | Hinsdale School District id9959 View details | United States | Education | ||
|
Hinsdale School District is an educational institution. It offers primary & high school education, job openings, professional development, financial information, and assessment. The school district was established in 1879 and is headquartered in Hinsdal,New Hampshire, 03451, United States |
|||||
| Ransomware | The Glendale Unified School District id9954 View details | United States | Education | ||
|
The Glendale Unified School District is a school district based in Glendale, California, United States. It consists of 20 elementary schools, 4 middle schools, 4 high schools and 3 facilities for homeschoolers and special-needs students.It currently has about 20,000 students |
|||||
| Ransomware | Campbell County Schools id9877 View details | Education | |||
|
Campbell County Schools is a school district operating schools in Campbell County, Kentucky in Greater Cincinnati. Its headquarters are in Alexandria. The number of students in the school district is more than 8000 thousand people |
|||||
| Ransomware | ACCU Reference Medical Lab id9871 View details | United States | Healthcare / Pharma | ||
|
ACCU Reference Medical Lab is a New Jersey-based full-service medical testing laboratory. Established in 2005, ACCU Reference Medical Lab serves healthcare providers in 19 states and employs over 750 professionals. The main office of the company is located at 1901 E Linden Ave Unit 25, Linden, New Jersey, 07036, United States. Over 1.2TB of data has been uploaded. |
|||||
| Ransomware | Sagent id9870 View details | United States | Services | ||
|
Sagent provides a comprehensive array of network services and helps their clients lower the cost of network ownership by using business analytics and network support services.The main office of the company is located at 120 Dividend Dr Ste 160, Coppell, Texas, 75019, United States |
|||||
| Ransomware | Bowden Barlow Law PA id9850 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
Bowden Barlow Law PA is a company that operates in the Legal Services industry. It employs 6-10 people and has $1M-$5M of revenue. The main office of the company is located at 3845 5th Ave N, Saint Petersburg, Florida, 33713, United States |
|||||
| Ransomware | Rosens Diversified Inc id9849 View details | United States | Communication / Marketing | ||
|
Founded in 1946, Rosens Diversified Inc (RDI) provides agriculture products, operates a beef processing company, conducts a fleet of semi trailer trucks, has a line of performance pet products, and has acquired an in-house marketing agency. The main office of the company is located at 8101 34th Ave S Ste 400, Bloomington, Minnesota, 55425, United States |
|||||
| Ransomware | Chetu id9792 View details | United States | IT | ||
|
Chetu is an American software development company providing industry—specific software solutions for businesses around the world. The main office is located at 1500 Concord Ter Ste 100, Sunrise, Florida, 33323, United States |
|||||
| Ransomware | Great Valley School District id9781 View details | Education | |||
|
Great Valley School District is located on the Philadelphia Main Line in eastern Chester County, Pennsylvania. The district provides public education for students in Charlestown, East Whiteland, and Willistown townships, and the borough of Malvern.At the moment, it has more than 4,000 students |
|||||
| Ransomware | Community Hospital id9669 View details | Healthcare / Pharma | |||
|
Community Hospital - founded in 1926 and headquartered in Tallassee, Alabama, Community Hospital provides healthcare services for the residents of Tallassee and surrounding areas. |
|||||
| Ransomware | CENTRE D'AUTO P.R.N. SALABERRY IN id9611 View details | Canada | Communication / Marketing | ||
|
CENTRE D'AUTO P.R.N. SALABERRY INC - provides professional repair and maintenance services for cars and light trucks to customers in the area of Vill Saint Loran. The main office of the company is located at 1755 Rue Grenet, Montreal, Quebec, H4L 2R6, Canada |
|||||
| Ransomware | McCray & Withrow id9610 View details | United States | Construction / Real Estate | ||
|
Olivetti, McCray & Withrow are Hilton Head Island Attorneys practicing in real estate, estate planning, probate, personal injury & medical malpractice. The company's office is located at 52 New Orleans Rd Fl 3, Hilton Head Island, South Carolina, 29928, United States |
|||||
| Ransomware | Toyota Financial id9595 View details | Japan | Finance / Legal / Insurance | ||
|
Toyota Motor Corporation is a Japanese multinational automotive manufacturer headquartered in Toyota City, Aichi, Japan. Toyota is one of the largest automobile manufacturers in the world, producing about 10 million vehicles per year. The leaked data is from Toyota Financial Services in Germany. Toyota Deutschland GmbH is an affiliated company held by Toyota Motor Europe (TME) in Brussels/Belgium and located in Köln (Cologne). |
|||||
| Ransomware | Moneris Solutions id9514 View details | Canada | Services | ||
|
Established in 2000 and headquartered in Toronto, Ontario, Canada, Moneris Solutions is a provider of payment processing solutions. The company offers credit, debit, wireless, and online payment services for merchants and offers electronic loyalty and stored-value. |
|||||
| Ransomware | Hopewell Area School District id9422 View details | Education | |||
|
Hopewell Area School District contains 5 schools (Hopewell Elementary, Independence Elementary, Margaret Ross Elementary, Hopewell Memorial Junior High School, Hopewell High School) and 2,107 students. The school district is located in Beaver County, Pennsylvania, USA. It serves the townships of Hopewell, Raccoon, and Independence. |
|||||
| Ransomware | Weidmann & Associates id9401 View details | United States | Construction / Real Estate | ||
|
Weidmann & Associates, Inc. was founded by Bill Weidmann in 1989. The company is engaged in the repair and reconstruction of facilities in the Greater Atlanta area.The main office of the company is located at 1875 Old Alabama Rd Ste 1310, Roswell, Georgia, 30076, United States |
|||||
| Ransomware | Unimed Blumenau id9400 View details | Brazil | Healthcare / Pharma | ||
|
Unimed Blumenau is a company that operates in the Health, Wellness and Fitness industry. It employs 1,001-2,000 people and has $500M-$1B of revenue. The company is headquartered in Blumenau, Santa Catarina, Brazil |
|||||
| Ransomware | Leaguers id9399 View details | United States | Communication / Marketing | ||
|
The Leaguers is a multi-purpose non-profit social services organization providing various services to the community for over 70 Years. The main office is located 405 University Ave 425, Newark, New Jersey, 07102, United States |
|||||
| Ransomware | Zon Beachside id9398 View details | United States | Public Sector | ||
|
Zon Beachside - a commercial center for the care of the elderly and disabled. The main office is located at 1894 S Patrick Dr, Indian Harbour Beach, Florida, 32937, United States |
|||||
| Ransomware | Canadian Psychological Association id9397 View details | Canada | NGOs / Associations | ||
|
The Canadian Psychological Association (CPA) is the primary organization representing psychologists throughout Canada. It was organized in 1939 and incorporated under the Canada Corporations Act, Part II, in May 1950. |
|||||
| Ransomware | Software Systems id9331 View details | United States | IT | ||
|
Software Systems is an American company providing data processing solutions for the education market and software systems for the Indiana education market. The company's main office is located at 432 S Emerson Ave Ste 200, Greenwood, Indiana, 46143, United States |
|||||
| Ransomware | Mount Carmel Care Center id9292 View details | Ireland | Healthcare / Pharma | ||
|
Mount Carmel Care Center, Inc. is a member of the Carmelite System, exclusively comprised of nursing and rehabilitation, independent living and assisted living facilities that span the Northeast and the Midwest, as well as a facility in Dublin, Ireland. |
|||||
| Ransomware | Jockey Club id9267 View details | Argentina | Communication / Marketing | ||
|
Jockey Club - founded on April 15, 1882. He is engaged in the administration of the Argentine racetrack, develops the regulation of racing, is a closed club for the elite of Argentina. The main office is located at 1702 Ave Bernabe Marquez, San Isidro, Buenos Aires, 1642, Argentina |
|||||
| Ransomware | Safpro id9186 View details | United Kingdom | Communication / Marketing | ||
|
Safpro is a company located in the UK and founded more than 40 years ago, specializing in the supply of work clothes and personal protective equipment for the support services sector throughout the UK. The main office of the company is located at Units 4-5 Ashville Industrial Estate Gloucester, GL2 5EU United Kingdom |
|||||
| Ransomware | EHPAD id9185 View details | France | Healthcare / Pharma | ||
|
EHPAD is a French commercial institution for the accommodation of elderly dependents (nursing home). The company has several branches in France. The main office is located at 69 Rue République, Trun, Normandy, 61160, France |
|||||