Ransomware Group intelligence
Medusa
InactiveTrack Medusa with 521 published victims and 12 known leak locations in a single intelligence view.
Overview
Medusa is tracked by Breach House as a ransomware group with 521 published victims.
United States is currently the most targeted country in this dataset.
12 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (12)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 10 | Onion service | Down checked 2h ago | hupxs7ps7md24kpz4lwsbra64abgxjx3pcc2wuca5ibawf2g5hlpfyqd.onion |
| Leak location 8 | Onion service | Down checked 2h ago | cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion |
| Leak location 6 | Onion service | Down checked 2h ago | s7lmmhlt3iwnwirxvgjidl6omcblvw2rg75txjfduy73kx5brlmiulad.onion |
| Leak location 12 | Onion service | Down checked 2h ago | 7aqabivkwmpvjkyefonf3gpy5gsubopqni7kcirsrq3pflckxq5zz4id.onion |
| Leak location 11 | Onion service | Down checked 2h ago | 62foekhv5humjrfwjdyd2dgextpbf5i7obguhwvfoghmu3nxpkmxlcid.onion |
| Leak location 4 | Onion service | Down checked 2h ago | dlmfciajg5s4vliyo5dhs5jyzhi2xr2fnkebul46lpf4xudtqiue4nid.onion |
| Leak location 7 | Web location | Down checked 2h ago | 45.9.148.39 |
| Leak location 5 | Onion service | Down checked 2h ago | kyfiw76eol6ph2mq7pi5e5tdvce37bicddhai62qhdc5ja6jdchz4qqd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion |
| Leak location 9 | Onion service | Down checked 2h ago | xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion |
| Leak location 2 | Onion service | Down checked 2h ago | medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion |
| Leak location 1 | Onion service | Down checked 2h ago | medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion |
Top Activity Sectors (17)
- Communication / Marketing 105
- Services 55
- Public Sector 54
- Healthcare / Pharma 52
- Education 40
- Finance / Legal / Insurance 32
- Construction / Real Estate 31
- IT 30
- Manufacturing / Engineering 28
- Retail / E-commerce 20
- Hospitality / Food & Beverage / Tourism 17
- Energy 13
- Transportation / Travel / Logistics 13
- Agriculture / Food 9
- NGOs / Associations 7
- Telecommunications 6
- Not identified 4
Typical Attacks (64)
▼How Medusa typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Medusa Group, Medusa Ransomware.
-
T1583.006 Web Services Resource Development
What they do: Medusa Group has utilized a file hosting service named filemail[.]com to host a zip file that contained malicious payloads that facilitated follow-on actions.
What that means: Adversaries may register for web services that can be used during targeting.
-
T1585.001 Social Media Accounts Resource Development
What they do: Medusa Group has created social media accounts including Telegram and X to publicize their activities.
What that means: Adversaries may create and cultivate social media accounts that can be used during targeting.
-
T1585.002 Email Accounts Resource Development
What they do: Medusa Group has created email accounts used in ransomware negotiations.
What that means: Adversaries may create email accounts that can be used during targeting.
-
T1588.002 Tool Resource Development
What they do: Medusa Group has obtained and leveraged numerous RMM services, along with publicly available tools used for scanning.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
T1608.002 Upload Tool Resource Development
What they do: Medusa Group has utilized a file hosting service called filemail[.]com to host a zip file that contained a RMM service such as ConnectWise.
What that means: Adversaries may upload tools to third-party or adversary controlled infrastructure to make it accessible during targeting.
-
T1650 Acquire Access Resource Development
What they do: Medusa Group has purchased user credentials and other sensitive data from Initial Access Brokers (IABs).
What that means: Adversaries may purchase or otherwise acquire an existing access to a target system or network.
-
What they do: Medusa Group has utilized compromised legitimate local and domain accounts within the victim environment to facilitate remote access and lateral movement sometimes in combination with PsExec.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: Medusa Group has leveraged public facing vulnerabilities in their campaigns against victim organizations to gain initial access.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1047 Windows Management Instrumentation Execution
What they do: Medusa Group has utilized Windows Management Instrumentation to query system information.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: Medusa Group has leveraged PowerShell for execution and defense evasion.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Medusa Group has used Windows Command Prompt to control and execute commands on the system to include ingress, network, and filesystem enumeration activities.
What that means: Adversaries may abuse the Windows command shell for execution.
-
What they do: Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy.
What that means: Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network.
-
T1106 Native API Execution
What they do: Medusa Group has leveraged Windows Native API functions to execute payloads.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1559 Inter-Process Communication Execution
What they do: Medusa Ransomware has leveraged the `CreatePipe` API to enable inter-process communication.
What that means: Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution.
-
T1559.001 Component Object Model Execution
What they do: Medusa Group has leveraged Component Object Model (COM) to bypass UAC.
What that means: Adversaries may use the Windows Component Object Model (COM) for local code execution.
-
T1569.002 Service Execution Execution
What they do: Medusa Group has utilized PsExec to execute scripts and commands within victim environments.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Medusa Group has modified Registry keys to elevate privileges, maintain persistence and allow remote access.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1136.002 Domain Account Persistence
What they do: Medusa Group has created a domain account within the victim environment.
What that means: Adversaries may create a domain account to maintain access to victim systems.
-
T1505.003 Web Shell Persistence
What they do: Medusa Group has utilized webshells to an exploited Microsoft Exchange Server.
What that means: Adversaries may backdoor web servers with web shells to establish persistent access to systems.
-
What they do: Medusa Group has used vulnerable or signed drivers to modify security solutions on victim devices.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: Medusa Group has attempted to bypass UAC using Component Object Model (COM) interface.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027.002 Software Packing Stealth
What they do: Medusa Group has packed the code of dropped kernel drivers using the packer ASM Guard.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1027.010 Command Obfuscation Stealth
What they do: Medusa Group has obfuscated PowerShell scripts with Base64 encoding.
What that means: Adversaries may obfuscate content during command execution to impede detection.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: Medusa Ransomware has utilized XOR encrypted strings.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.003 Clear Command History Stealth
What they do: Medusa Group has cleared command history by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.
What that means: In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.
-
T1070.004 File Deletion Stealth
What they do: Medusa Group has deleted previously installed tools.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: Medusa Ransomware has decoded XOR encrypted strings prior to execution in memory.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1218.014 MMC Stealth
What they do: Medusa Group has leveraged Microsoft Management Console (MMC) to facilitate lateral movement and to interact locally or remotely with victim devices using the command `mmc.exe compmgmt.msc /computer:{hostname/ip}`.
What that means: Adversaries may abuse mmc.exe to proxy execution of malicious .msc files.
-
T1564.003 Hidden Window Stealth
What they do: Medusa Group has utilized the `ShowWindow` API function to hide the current window.
What that means: Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
-
T1679 Selective Exclusion Stealth
What they do: Medusa Ransomware has avoided specified files, file extensions and folders to ensure successful execution of the payload and continued operations of the impacted device.
What that means: Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution.
-
T1553.002 Code Signing Defense Impairment
What they do: Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools.
What that means: Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Medusa Group has terminated antivirus services utilizing the gaze.exe executable and utilizing `psexec.exe`.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1686 Disable or Modify System Firewall Defense Impairment
What they do: Medusa Group has utilized PsExec to execute batch scripts that modify firewall settings.
What that means: Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action.
-
T1690 Prevent Command History Logging Defense Impairment
What they do: Medusa Group has removed PowerShell command history through the use of the PSReadLine module by running the PowerShell command `Remove-Item (Get-PSReadlineOption).HistorySavePath`.
What that means: Adversaries may impair command history logging to hide commands they run on a compromised system.
-
T1003.001 LSASS Memory Credential Access
What they do: Medusa Group has leveraged Mimikatz to dump LSASS to harvest credentials.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1003.003 NTDS Credential Access
What they do: Medusa Group has accessed the ntds.dit file to engage in credential dumping.
What that means: Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights.
-
T1007 System Service Discovery Discovery
What they do: Medusa Ransomware has leveraged an encoded list of services that it designates for termination.
What that means: Adversaries may try to gather information about registered local system services.
-
T1016 System Network Configuration Discovery Discovery
What they do: Medusa Group has obtained host network details utilizing the command `cmd.exe /c ipconfig /all`.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1018 Remote System Discovery Discovery
What they do: Medusa Group has used PDQ Inventory to get an inventory of the endpoints on the network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1033 System Owner/User Discovery Discovery
What they do: Medusa Group has utilized PsExec to execute `quser` to discover the user session information.
What that means: Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
-
T1046 Network Service Discovery Discovery
What they do: Medusa Group has the capability to use living off the land (LOTL) binaries to perform network enumeration.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1057 Process Discovery Discovery
What they do: Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1069.002 Domain Groups Discovery
What they do: Medusa Group has utilized the `net group` command to query domain groups within the victim environment.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1082 System Information Discovery Discovery
What they do: Medusa Group has leveraged `cmd.exe` to identify system info `cmd.exe /c systeminfo`.
What that means: An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
-
T1083 File and Directory Discovery Discovery
What they do: Medusa Group has searched for files within the victim environment for encryption and exfiltration.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.001 Local Account Discovery
What they do: Medusa Group has leveraged `net user` for account discovery.
What that means: Adversaries may attempt to get a listing of local system accounts.
-
T1124 System Time Discovery Discovery
What they do: Medusa Ransomware has discovered device uptime through `GetTickCount()`.
What that means: An adversary may gather the system time and/or time zone settings from a local or remote system.
-
T1135 Network Share Discovery Discovery
What they do: Medusa Group has identified network shares using `cmd.exe /c net share`.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1518.001 Security Software Discovery Discovery
What they do: Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.
What that means: Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
-
T1652 Device Driver Discovery Discovery
What they do: Medusa Group has queried drivers on the victim device through the command `driverquery`.
What that means: Adversaries may attempt to enumerate local device drivers on a victim host.
-
T1680 Local Storage Discovery Discovery
What they do: Medusa Ransomware has enumerated logical drives on infected hosts.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: Medusa Group has used RDP to conduct lateral movement and exfiltrate data.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: Medusa Group has utilized legitimate software services such as PDQ Deploy to transfer malicious binaries and tools to other victimized hosts within the target environment.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1071.001 Web Protocols Command and Control
What they do: Medusa Group has communicated through reverse or bind shells over port 443 (HTTPS).
What that means: Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
-
T1090.003 Multi-hop Proxy Command and Control
What they do: Medusa Group has used TOR nodes for communications.
What that means: Adversaries may chain together multiple proxies to disguise the source of malicious traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Medusa Group has leveraged certutil, PowerShell, and Windows Command to download additional tools to include RMM services.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1219 Remote Access Tools Command and Control
What they do: Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1573.002 Asymmetric Cryptography Command and Control
What they do: Medusa Group has used HTTPS for command and control.
What that means: Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: Medusa Group has utilized Rclone to exfiltrate data from victim environments to cloud storage.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Medusa Group has deleted recovery files such as shadow copies using `vssadmin.exe`.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1529 System Shutdown/Reboot Impact
What they do: Medusa Group has manually turned off and encrypted virtual machines.
What that means: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
-
T1657 Financial Theft Impact
What they do: Medusa Group has stolen and encrypted victims' data in order to extort victims into paying a ransom.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (27)
▼Software Medusa has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
!!!READ_ME_MEDUSA!!!.txt
$$\ $$\ $$$$$$$$\ $$$$$$$\ $$\ $$\ $$$$$$\ $$$$$$\ $$$\ $$$ |$$ _____|$$ __$$\ $$ | $$ |$$ __$$\ $$ __$$\ $$$$\ $$$$ |$$ | $$ | $$ |$$ | $$ |$$ / \__|$$ / $$ | $$\$$\$$ $$ |$$$$$\ $$ | $$ |$$ | $$ |\$$$$$$\ $$$$$$$$ | $$ \$$$ $$ |$$ __| $$ | $$ |$$ | $$ | \____$$\ $$ __$$ | $$ |\$ /$$ |$$ | $$ | $$ |$$ | $$ |$$\ $$ |$$ | $$ | $$ | \_/ $$ |$$$$$$$$\ $$$$$$$ |\$$$$$$ |\$$$$$$ |$$ | $$ | \__| \__|\________|\_______/ \______/ \______/ \__| \__| -----------------------------[ Hello, [snip] !!! ]-------------------------- WHAT HAPPEND? ------------------------------------------------------------ 1. We have PENETRATE your network and COPIED data. * We have penetrated entire network including backup system and researched all about your data. * And we have extracted all of your networks including sub offices and your service clients networks valuable data and copied them to private cloud storage. 2. We have ENCRYPTED some your files. While you are reading this message, it means you found your files and data has been ENCRYPTED by world's strongest ransomware. We have access to all of your sub offices and client service networks but didn't lock them all for your brand and privacy. We can solve this issue sliently and smoothly without 3rd parties and we decided lock only some of your main network only. But don't worry, we can restore everything to the original without harming your business. There is only one possible way to get back your systems and business - CONTACT us via LIVE CHAT and pay for the special MEDUSA DECRYPTOR and DECRYPTION KEYs, Data deletion, Keep silent in media. This MEDUSA DECRYPTOR will restore your entire network, This will take less than 1 business day. WHAT GUARANTEES? --------------------------------------------------------------- We can post your data to the public and send emails to your customers. We have professional OSINTs and media team for leak data to telegram, facebook, twitter channels and top news websites. Have a look about us on twitter. You can suffer significant problems due disastrous consequences, leading to loss of valuable intellectual property and other sensitive information, costly incident response efforts, information misuse/abuse, loss of customer trust, brand and reputational damage, legal and regulatory issues. After paying for the data breach and decryption, we guarantee that your data will never be leaked and this is also for our reputation. YOU should be AWARE! --------------------------------------------------------------- If you're not in main chile office, inform your supervisors and stay calm! We will speak only with an authorized person. It can be the CEO, top management, etc. In case you are not such a person - DON'T CONTACT US! Your decisions and action can result in serious harm to your company! If you do not contact us within 3 days, We will start publish your case to our official blog and everybody will start notice your incident! If you do not contact us within 5 days, We will start publish your case and leak video on all social channels and send emails to your customers! --------------------[ Official blog tor address ]-------------------- Using TOR Browser(https://www.torproject.org/download/): http://medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion/ CONTACT US! ----------------------[ Your company live chat address ]--------------------------- Using TOR Browser(https://www.torproject.org/download/): http://medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion/[snip] Or Use Tox Chat Program(https://qtox.github.io/) Add user with our tox ID and wait 24h : 4AE245548F2A225882951FB14E9BF87EE01A0C10AE159B99D1EA62620D91A372205227254A9F Our support email: ( [email protected] ) Company identification hash: [snip]
!!!READ_ME_MEDUSA!!!_2.txt
$$\ $$\ $$$$$$$$\ $$$$$$$\ $$\ $$\ $$$$$$\ $$$$$$\ $$$\ $$$ |$$ _____|$$ __$$\ $$ | $$ |$$ __$$\ $$ __$$\ $$$$\ $$$$ |$$ | $$ | $$ |$$ | $$ |$$ / \__|$$ / $$ | $$\$$\$$ $$ |$$$$$\ $$ | $$ |$$ | $$ |\$$$$$$\ $$$$$$$$ | $$ \$$$ $$ |$$ __| $$ | $$ |$$ | $$ | \____$$\ $$ __$$ | $$ |\$ /$$ |$$ | $$ | $$ |$$ | $$ |$$\ $$ |$$ | $$ | $$ | \_/ $$ |$$$$$$$$\ $$$$$$$ |\$$$$$$ |\$$$$$$ |$$ | $$ | \__| \__|\________|\_______/ \______/ \______/ \__| \__| -----------------------------[ Hello, [snip] !!! ]-------------------------- Sorry to interrupt your busy business. WHAT HAPPEND? ------------------------------------------------------------ 1. We have PENETRATE your network and COPIED data. We have penetrated your entire network and researched all about your data. And we have copied all of your confidential data and uploaded to private storage. * You're running a highly valued business and your data was very crucial. 2. We have ENCRYPTED your files. While you are reading this message, it means your files and data has been ENCRYPTED by world's strongest ransomware. Your files have encrypted with new military-grade encryption algorithm and you can not decrypt your files. But don't worry, we can decrypt your files. There is only one possible way to get back your computers and servers, keep your privacy safe - CONTACT us via LIVE CHAT and pay for the special MEDUSA DECRYPTOR and DECRYPTION KEYs. This MEDUSA DECRYPTOR will restore your entire network within less than 1 business day. WHAT GUARANTEES? --------------------------------------------------------------- We can post all of your critial data to the public and send emails to your competitors. We have professional OSINTs and media team for leak data to telegram, facebook, twitter channels and top news websites. You can easily search about us. You can suffer significant problems due to disastrous consequences, leading to loss of valuable intellectual property and other sensitive information, costly incident response efforts, information misuse/abuse, loss of customer trust, brand and reputational damage, and legal and regulatory issues. After paying for the data breach and decryption, we guarantee that your data will never be leaked and make everything silent, this is also for our reputation. YOU should be AWARE! --------------------------------------------------------------- We will speak only with an authorized person. It can be the CEO, top management etc. In case you ar not such a person - DON'T CONTACT US! Your decisions and action can result in serious harm to your company! Inform your supervisors and stay calm! If you do not contact us within 48 hours, We will start publish your case to our official blog and everybody will start notice your incident! --------------------[ Telegram channel ]-------------------- https://t.me/+yXOcSjVjI9tjM2E0 --------------------[ Official blog tor address ]-------------------- Using TOR Browser(https://www.torproject.org/download/): http://xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion/ http://cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion/ CONTACT US! ----------------------[ Your company live chat address ]--------------------------- Using TOR Browser(https://www.torproject.org/download/): http://uyku4o2yg34ekvjtszg6gu7cvjzm6hyszhtu7c55iyuzhpr4k5knewyd.onion/[snip] Backup Mirrors: http://5ar4vuckm3k7osdlzskqkaqmqr4jjpmdikuotmlpkrbsxx7ard3xetyd.onion/[snip] --------------------[ Or Use Tox Chat Program(https://utox.org/uTox_win64.exe) ]-------------------- Add user with our tox ID : 061AA6BDE8F6DE6C92F0D6E077359BF6911FCAF80030E82B3A3DB65E63C8011343D34F956FEC Our support email: ( [email protected] ) Company identification hash: [snip]
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (521)
Search, filter and paginate the victim timeline for Medusa. Showing 401–500 of 521.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Beaver Lake Cree Nation id9184 View details | Canada | Communication / Marketing | ||
|
The Beaver Lake Cree Nation (Canada) is a First Nations band government located 105 kilometres (65 mi) northeast of Edmonton, Alberta, representing people of the Cree ethno-linguistic group in the area around Lac La Biche, Alberta, where the band office is currently located. |
|||||
| Ransomware | Native Counselling Services of Alberta id9183 View details | Canada | Services | ||
|
Native Counselling Services of Alberta (NCSA) is a non—profit, non-political organization of indigenous peoples with no religious affiliation, providing legal and various other services for indigenous peoples. It is registered in accordance with the Albert Societies Act (Canada). Main office address - 14904 121A Ave NW Edmonton, Alberta T5V 1A3, CA |
|||||
| Ransomware | ATI Traduction id9109 View details | France | Other | ||
|
ATI Traduction is a French company working in the field of translation and localization. The company is headquartered in Roubaix, Hauts-de-France, France. |
|||||
| Ransomware | EDB id9108 View details | Italy | Communication / Marketing | ||
|
EDB is an Italian company founded in 1995, engaged in automation of production processes, development and production of printed circuit boards and embedded systems in various markets. The main office of the company is located at 23 Piazza Vantini, Rezzato, Lombardy, 25086, Italy |
|||||
| Ransomware | Global Product Sales id9107 View details | United States | Retail / E-commerce | ||
|
Global Product Sales is an American company working in the field of agriculture. The main office of the company is located at 1018 E Oleander St, Lakeland, Florida, 33801, United States |
|||||
| Ransomware | Symposia Organizzazione Congressi S.R.L id9106 View details | NGOs / Associations | |||
|
Symposia Organizzazione Congressi S.R.L is an Italian company founded 30 years ago, specializing in the organization of events. The main office of the company is located at Palazzo del Melograno ("Pomegranate Palace") in Campetto in Genoa |
|||||
| Ransomware | Believe Productions id9102 View details | United States | Manufacturing / Engineering | ||
|
Believe Productions is a company based in Denver, Colorado, founded in 1997 as a link between music education and the music industry. The main office of the company is located at 9540 Maroon Cir Unit 100, Englewood, Colorado, 80112, United States |
|||||
| Ransomware | Neodata id9058 View details | Spain | Construction / Real Estate | ||
|
Neodata is a Spanish company engaged in the development of ERP software designed for the meat and poultry industry. The main office of the company is located at 51 Calle Llull 3º 4ª, Barcelona, Catalonia, 08005, Spain |
|||||
| Ransomware | Evasión id9057 View details | Spain | Communication / Marketing | ||
|
Evasión is a Spanish company providing digital postproduction services for the FILM, ADVERTISING, TELEVISION and EVENT markets. The main office of the company is located at 8 2º izq. San Bernardo, Madrid, Madrid, 28015, Spain |
|||||
| Ransomware | SIMTA id9056 View details | Italy | Manufacturing / Engineering | ||
|
SIMTA is an Italian company founded in 1949, specializing in the production of fabrics for furniture. The main office of the company is located at 185 Corso Svizzera, Turin, Piedmont, 10149, Italy |
|||||
| Ransomware | ZOUARY & Associés id9055 View details | Services | |||
|
ZOUARY & Associés - a French company that provides business accounting support and audit services. The main office is located at 25 B RUE PASTEUR ENGHIEN LES BAINS, 95880, FR |
|||||
| Ransomware | Agència Catalana de Notícies (ACN) id8985 View details | Hospitality / Food & Beverage / Tourism | |||
|
The Agència Catalana de Notícies (ACN) is one of the first digital news agencies established in Europe and has been operating since 1999. The Spanish office of the company is located at Avinguda Josep Tarradellas, 20, 30, 2a planta 08029 Barcelona |
|||||
| Ransomware | Somagic id8946 View details | France | Hospitality / Food & Beverage / Tourism | ||
|
The Somagic is a French company in the production of solid-fuel barbecues and barbecues, the company was founded in 1981. The main office of the company is located at 1 A Rd 975 Cs 20010, La Gente, Bourgogne-Franche-Comte, 71290, France. The credit of this company itself and top management was the worst among the we made deals this year. |
|||||
| Ransomware | Windak id8931 View details | United States | Energy | ||
|
Windak is a cable packaging equipment manufacturing company founded in Sweden in 1994. The company's main office is located at 1661 4th St SW, Conover, North Carolina, 28613, United States |
|||||
| Ransomware | Karam Chand Thapar & Bros Coal Sales id8929 View details | India | Retail / E-commerce | ||
|
Karam Chand Thapar & Bros Coal Sales - it is the flagship company of the KCT Group of companies. It was founded by the late Karam Chand Axe in 1943. Today, the company provides coal services and logistics.The company's office is located 25 Brabourne Rd, Kolkata, West Bengal, 700084, India |
|||||
| Ransomware | Acoustic Center id8871 View details | Services | |||
|
Acoustic Center is an Italian regional company for the distribution of hearing systems, the distribution and use of hearing aids and related services since 1958. |
|||||
| Ransomware | LANDSTAR POWER ONTARIO INC id8870 View details | Energy | |||
|
LANDSTAR POWER ONTARIO INC - canadian company engaged in the purchase of used batteries and various scrap metal with further resale. The company's office is located at 9 Stewart Ct Orangeville, Ontario, L9W 3Z9 CANADA |
|||||
| Ransomware | Franktronics, Inc id8757 View details | United States | IT | ||
|
Franktronics, Inc. is an information technology and services company based out of 3618 George Washington Memorial Hwy, Hayes, Virginia, 23072, United States. |
|||||
| Ransomware | Philippine Health Insurance id8756 View details | Philippines | Healthcare / Pharma | ||
|
The Philippine Health Insurance Corporation (PhilHealth) was established in 1995 to provide universal health insurance in the Philippines. It is a tax-exempt, state-owned and controlled corporation (GOGC) of the Philippines, subordinate to the Ministry of Health. Company came to the tor chat but didn't answer for the payment yet. |
|||||
| Ransomware | Chait id8708 View details | United States | Services | ||
|
Chait & Company is a Los Angeles—based firm offering a wide range of architectural design, general contracting and construction management services, recognized in 1994. The company's main office is located at 14931 a Celica St Ste A, Van Nuys, California, 91411, United States |
|||||
| Ransomware | Gulf American Lines id8707 View details | United States | Transportation / Travel / Logistics | ||
|
Headquartered in Berkeley Heights, New Jersey, Gulf American Line is a leader in freight forwarding, warehousing and logistics provider. The company occupies a leading position in terms of the volume of transported goods in the United States |
|||||
| Ransomware | Auckland Transport id8669 View details | New Zealand | Transportation / Travel / Logistics | ||
|
Founded in 2010, Auckland Transport is a company that is responsible for the region's transport infrastructure and public transport including roads and footpaths, cycling, parking, and public transportation. Auckland Transport is located in New Zealand |
|||||
| Ransomware | Wave Hill id8571 View details | United States | Public Sector | ||
|
Wave Hill is a community garden and cultural center located in New York City. The company's head office is located at 675 W 252nd St, Bronx, New York, 10471, United States |
|||||
| Ransomware | Steripharma id8570 View details | Morocco | Healthcare / Pharma | ||
|
Steripharma is a Moroccan pharmaceutical laboratory founded in 1999. Cooperates with both public and private clients in Morocco and Africa. The company's head office is located at 429 So. West St, Syracuse, New York 13202, US |
|||||
| Ransomware | Betton France id8463 View details | France | Public Sector | ||
|
Administration of the city of Betton (France). The concrete is located in the center of the Rhine agglomeration, 7 km north of Rennes, near the Rennes-Saint-Malo axis and on the Mont Saint-Michel tourist route. Currently, the population of the city is about 11,000 people. |
|||||
| Ransomware | Jules B id8462 View details | United Kingdom | Retail / E-commerce | ||
|
Jules B is a chain of designer clothing stores for men and women in England founded for over 30 years. The company's head office is located at Yellow Brick House, Newcastle upon Tyne, Tyne and Wear NE1 2TY, GB |
|||||
| Ransomware | Aranui Cruises id8364 View details | United States | Public Sector | ||
|
Aranui Cruises is the oldest cruise operator in French Polynesia, having been founded 35 years ago. The company has a ship made to order ship "Aranui 5" designed for VIP level cruise holidays. The American office of the company is located at 2028 El Camino Real So Te B, San Mateo, California, 94403, United States |
|||||
| Ransomware | Skynet id8363 View details | United States | Telecommunications | ||
|
Skynet (https://www.skynetwisp.com/) provides Internet access services, both for the private segment of the market and for public institutions. The company's main office is located at 6630 Fm 1463 Rd 255 Step 500, Katy, Texas, 77494, United States |
|||||
| Ransomware | LEN Italia id8299 View details | Education | |||
|
LEN Italia– Learning Education Network is a cooperative company that engages in professional training by planning and providing training and consulting activities. Founded in 2005, LEN has a team of more than 70 professionals available to educational institutions, companies, public administrations, non-profit organizations and individuals for any type of training and consultation. |
|||||
| Ransomware | Durham Fasteners id8298 View details | Canada | Services | ||
|
Durham Fasteners is a family-owned company whose roots in the business were laid in 1981. The company specializes in solutions for fasteners, packaging, as well as worldwide deliveries. The company's office is located at 757 Mckay Rd, Block 9, Pickering, Ontario, 1 3C8, Canada |
|||||
| Ransomware | Axis Elevators id8297 View details | United Kingdom | Other | ||
|
Axis Elevators - is one of the largest elevator companies in the UK and Ireland, engaged in the installation, maintenance and modernization of elevators and escalators, as well as other types of lifts. The company was founded more than 100 years ago. The main office of the company is located at 1, 65 Glass Hill Street, London, Greater London, SE10, United Kingdom |
|||||
| Ransomware | Novi Pazar put ad id8206 View details | Serbia | Manufacturing / Engineering | ||
|
Novi Pazar put ad is a company that operates in the Civil Engineering industry. It employs 251-500 people and has $10M-$25M of revenue. The company is headquartered in Novi Pazar, 36300, Serbia |
|||||
| Ransomware | The International Civil Defense Organization id8205 View details | NGOs / Associations | |||
|
The International Civil Defense Organization (ICDO) is an intergovernmental organization whose goal is to promote the development by States of structures that protect and assist the population, as well as the protection of property and the environment from natural disasters or man-made disasters. It was founded in 1931.It consists of 60 Member States, 16 observer States and 23 associate members. |
|||||
| Ransomware | Sartrouville France id8204 View details | France | Public Sector | ||
|
Sartrouville is a commune in the Yvelines department, Île-de-France, north central France. it is located in the north-western suburbs of Paris, 17.1 km from the center of Paris. It employs 501-1,000 people and has $100M-$250M of revenue. Is headquartered in Sartrouville, Ile-de-France, 78500, France. |
|||||
| Ransomware | Postel SpA id8146 View details | Italy | IT | ||
|
Postel SpA offers computer software for sale. The Company provides software products and management services including document management, direct marketing, and e-procurement software and related services. Postel operates throughout Italy, the company's head office is located at 5 Via Ricerca Scientifica, Padova, Veneto, 35127, Italy |
|||||
| Ransomware | CB Energy Australlia id8131 View details | Australia | Energy | ||
|
CB Group Australia provide a broad range of services across the construction industry in project management, civil, electrical and maintenance disciplines. The company was founded in 1946. The company's central office is located at 15 Production Ave, Molendinar, Queensland, 4214, Australia |
|||||
| Ransomware | Borets (Levare.com) id8130 View details | Manufacturing / Engineering | |||
|
Borets (Levare.com) is Headquartered in Houston, Texas, with an international headquarters in Dubai, Borets is a global provider specializing in the engineering, manufacture, sales and service of Electric Submersible Pump systems. Uploaded Data Size: 1TB |
|||||
| Ransomware | Avatier ida7105 View details | United States | Services | ||
|
Avatier is a US-based services and software company headquartered in Pleasanton, California. It provides identity management, single sign-on, password management, and broader IT services that support security, compliance, and user access operations for enterprises. The company describes its offerings as AI-powered identity and access management solutions for enterprise security and workflow automation. Avatier was listed as a ransomware victim associated with Medusa. |
|||||
| Ransomware | Emerson School District id8082 View details | United States | Education | ||
|
The Emerson School District is a comprehensive community public school district that serves students in pre-kindergarten through twelfth grade from Emerson, in Bergen County, New Jersey, United States. There are currently about 1,200 students enrolled in the school district. |
|||||
| Ransomware | Ace Micromatic Group id7976 View details | India | Communication / Marketing | ||
|
Ace Micromatic Group is India's largest machine tool conglomerate with a market presence in several countries across Asia, Australia, Middle East, North & South America and Europe. |
|||||
| Ransomware | St Landry Parish School Board id7975 View details | Education | |||
|
St Landry Parish School Board is a school district based in Opelusas, Louisiana. The area includes primary, secondary and secondary schools. At the moment, more than 14,000 students are studying in them. |
|||||
| Ransomware | The Sinbad Club id7439 View details | Egypt | Services | ||
|
The Sinbad Club company, founded in 1992, offers a wide range of services for recreation on the Red Sea coast in Egypt. The main office of the company is located at 10 Elmenya Street, Cairo, Cairo, HELIOPOLIS, Egypt. |
|||||
| Ransomware | Sun Pain Management id7415 View details | United States | Services | ||
|
Sun Pain Management and Spine Specialists treats clinic, whose head office is located at 5501 N 19th Ave Ste 103, Phoenix, Arizona, 85015, United States offers a wide range of procedures for patients suffering from chronic pain. In total, there are five centers of this clinic in the United States. |
|||||
| Ransomware | Cafe Britt id7414 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
Cafe Britt is a company engaged in processing beans and making coffee in Costa Rica with subsequent export to global markets. The company's product line also includes other products, such as coffee, chocolate and cookies, etc. The head office is located at 2960 NW 72nd Ave, Miami, Florida, 33122, United States |
|||||
| Ransomware | DTD Express id7354 View details | United Kingdom | Communication / Marketing | ||
|
DTD Express provides international parcel delivery services. The company specializes in meeting the import and export needs of Asia (India, Pakistan), the Far East (China, Hong Kong), the USA and Europe. The company's head office is located at 30b Melton Rd, Leicester, Leicester, L4 5 EA, United Kingdom |
|||||
| Ransomware | Health Springs Medical Center id7350 View details | Healthcare / Pharma | |||
|
Health Springs Medical Center is a clinic located at 209 S COLLEGE ST HEATH SPRINGS. Currently, 8 doctors of the Health Springs Medical Center work in 6 specialized fields of medicine, as well as students are trained |
|||||
| Ransomware | Nini Collection Ltd (Nini's Jewels) id7349 View details | United States | Public Sector | ||
|
Nini Collection Ltd is a company that operates in the Luxury Goods & Jewelry industry. It employs 6-10 people and has $1M-$5M of revenue. The company is headquartered in Westheimer Rd Ste 330, Houston, Texas, 77056, United States |
|||||
| Ransomware | Tracker de Colombia SAS id7181 View details | Communication / Marketing | |||
|
The organization, which was founded in 1994 and working in 9 countries of Latin America, which develops, designs, develops, produces and sells products, specialized software, services and comprehensive solutions in the field of security, monitoring, determination of location, identification, remote management and relational marketing. |
|||||
| Ransomware | Yunus Emre Institute Turkey id7113 View details | Türkiye | Education | ||
|
The Yunus Emre Institute (Yunus Emre Enstitüsü) is a worldwide non-profit organization established by the Turkish government in 2007. It is aimed at popularizing the Turkish language and culture around the world. It has 62 centers in 52 countries of the world. |
|||||
| Ransomware | Mutuelle LMP id7105 View details | France | Finance / Legal / Insurance | ||
|
Mutuelle LMP is a French company operating in the field of insurance. The company employs 51-100 people, and the revenue is from 10 to 25 million dollars. The company was founded more than 167 years ago, and provides insurance protection of more than 45,000 people. |
|||||
| Ransomware | Luna Hotels & Resorts id7104 View details | Portugal | Hospitality / Food & Beverage / Tourism | ||
|
Luna Hotels & Resorts is one of Portugal's most famous hotel brands. The company invests, creates, controls and offers a number of services for the whole family, sports sector and corporate segment. The main office is located at Lote H1 Avenida Da Marina, Vilamoura, Faro, 8125-401, Portugal |
|||||
| Ransomware | Real Estate Systems Integrator id7016 View details | United States | Construction / Real Estate | ||
|
RESI was established in 1994 with the purpose of providing REALTORS® with the technology necessary to enhance productivity and broaden their reach. The main office of the company is located at: 560 Lincoln Rd Ste 203, Miami Beach, Florida, 33139, United States |
|||||
| Ransomware | Universitas Matthiae Belii association id7015 View details | Slovakia | Education | ||
|
Matej Bel University (commonly referred as Matej Bel or UMB), (Slovak: Univerzita Mateja Bela) is a public research university in the central Slovak town of Banská Bystrica. The university was established in 1992. At the moment, more than 6,000 students are studying at the university. |
|||||
| Ransomware | Praxis Energy Agents id6960 View details | United States | Energy | ||
|
Praxis Energy Agents is an international bunkering trading company founded in Greece in 1993 and currently operating through four offices in Singapore, Dubai, Hamburg and New York. The company's head office is located at 2603 Augusta Dr Ste 1260, Houston, Texas, 77057, United States |
|||||
| Ransomware | FHR Electric id6930 View details | Services | |||
|
FHR Electric offers cost-effective electrical repair services in Scottsdale, Arizona. The main office of the company is located at 7720 E Gelding Dr. Scottsdale AZ 85260 |
|||||
| Ransomware | Salem Community Schools id6877 View details | Education | |||
|
Salem Community Schools is a public school district located in SALEM, IN. It has 1,762 students in grades PK, K-12 with a student-teacher ratio of 15 to 1. |
|||||
| Ransomware | GAE Construction id6812 View details | United Kingdom | Construction / Real Estate | ||
|
Website: https://gae-construction.co.uk/ GAE Construction, offers construction services at all levels to both large and small clients in London and the North-East of England. |
|||||
| Ransomware | Comisión Nacional de Valores id6811 View details | Argentina | Finance / Legal / Insurance | ||
|
Regulatory agency in charge of authorizing IPOs and securing compliance by market participants with federal securities laws in the Argentine Republic. It supervises brokerage firms, issuers, stock exchanges, mutual funds and credit rating agencies. It is a member of IOSCO. More than 1.5TB of documents & database dumps has been uploaded. |
|||||
| Ransomware | Kramer Enterprises id6790 View details | Communication / Marketing | |||
|
Kramer Enterprises was founded in 1999, provides services in Southern Wisconsin for the construction of flat surfaces and specializes in stamped and colored decorative concrete. The company's clients include Fort Atkinson, Jefferson, Whitewater, Watertown, Janesville, Cambridge and surrounding areas. |
|||||
| Ransomware | Tour Partner Group id6782 View details | United Kingdom | Education | ||
|
Tour Partner Group is a holding company dealing with hotels and many others, Irish welcome tours and authentic holidays. The company was founded in 1992, the central office is located at 66-68 College Rd Fl 5, London, Essex, CO1 1BE, United Kingdom |
|||||
| Ransomware | Farmacias Los Hidalgos id6743 View details | Dominican Republic | Agriculture / Food | ||
|
Farmacias Los Hidalgos is a health, wellness and fitness company founded in 1975, based in the Dominican Republic at Avenue 27 de Febrero No. 241 in Ensanche Popcorn. |
|||||
| Ransomware | Concremat constructions id6742 View details | Brazil | Construction / Real Estate | ||
|
Founded in 1972 and headquartered in Rio de Janeiro, Concremat Companies provides construction and engineering services. The company offers services such as urban and regional development studies, environmental management systems, and a sustainable development plan for territories |
|||||
| Ransomware | BilgeAdam Software id6665 View details | IT | |||
|
BilgeAdam operates as one of the subsidiaries of BilgeAdam IT Group, founded in 1997. The headquarters of the company, which includes the sts Research Center, subordinate to the Ministry of Industry and Technology, is located at 4 b3 Sarıyer, Istanbul, 34396, Turkey. The main areas of activity are IOT management, automation, communications, network and security. Leak includes their internal source codes and recent live screenshots of their works. |
|||||
| Ransomware | Fiduagraria id6658 View details | Colombia | Public Sector | ||
|
Fiduagraria is a joint-stock company of a mixed economy, subject to the State regime of an industrial and commercial enterprise, in accordance with the national order, associated with the Ministry of Agriculture and Rural Development, under the control and supervision of the Financial Administration of Colombia and legally registered on the basis of Public Act No. 1199 of February 18, 1992 with the main address in the city of Bogota. |
|||||
| Ransomware | Trabzonspor Football Club id6626 View details | Türkiye | Public Sector | ||
|
Trabzonspor Kulübü ( German Sportklub Trabzon ) is a sports club from the Turkish port city of Trabzon. The club, founded on August 2, 1967, is best known for its football department, which was Turkish champion six times between 1976 and 1984. Trabzonspor is one of Turkey's big four and is regularly ranked as a championship contender. |
|||||
| Ransomware | Amaszonas S.A. id6597 View details | Bolivia, Plurinational State of | Transportation / Travel / Logistics | ||
|
Lnea Aérea Amaszonas S.A. ("Amaszonas") is a Bolivian regional airline based at the Viru Viru International Airport in Santa Cruz. The operator was founded in 1999 and provides scheduled regional services. Amaszonas is owned by the group of Latin American airlines |
|||||
| Ransomware | Leland Campbell LLP law firm id6596 View details | Finance / Legal / Insurance | |||
|
Leland Campbell LLP is the largest law firm in Yorkton and the district, employing 8 lawyers and staff. The firm's services include real estate, wills and estate, criminal law, family law, civil litigation and commercial/commercial law, to name just a few. |
|||||
| Ransomware | Loreto Normanhurst id6493 View details | Australia | Education | ||
|
Loreto Normanhurst is an independent Catholic, primary and secondary day and boarding school for girls, located in Normanhurst, a suburb on the upper North Shore of Sydney, New South Wales, Australia. Established in 1897, Loreto has a current enrolment of approximately 1,175 students from Year 5 to Year 12, including approx. 185 boarders, and is the largest girls' boarding school in New South Wales. |
|||||
| Ransomware | SIGMA id6492 View details | United States | Services | ||
|
SIGMA is a company located at 4915 Ambroise Lafortune Ste 100, Boisbriand, Quebec, J7H 0A4, Canada, providing IT services specializing in the development and implementation of an integrated management system (IMS) for manufacturing (MRP/ERP) and distribution companies. |
|||||
| Ransomware | Al Tamimi Law Firm id6474 View details | United Arab Emirates | Finance / Legal / Insurance | ||
|
Founded by Essam Al Tamimi in 1989, Al Tamimi & Company has become the largest law firm in the Middle East with offices in Bahrain, Egypt, Iraq, Jordan, Kuwait, Oman, Qatar, Saudi Arabia and the United Arab Emirates. The firm employs more than 360 lawyers and has over 720 staff in total. |
|||||
| Ransomware | BAMSI id6444 View details | Healthcare / Pharma | |||
|
BAMSI is a private, non-profit social services organization that provides behavioral health and public health services to adults and children with developmental disabilities and mental illnesses. BAMSI was founded in 1975 and is headquartered in Brockton, Massachusetts, with 50,000 patients served annually. |
|||||
| Ransomware | HostAfrica id6431 View details | South Africa | Communication / Marketing | ||
|
HostAfrica was founded in 2015 in Cape Town with the mission to provide high-performance servers and hosting services in South Africa at a reasonable price. HostAfrica is based in Cape Town, South Africa. |
|||||
| Ransomware | Wallick Communities id6429 View details | Construction / Real Estate | |||
|
Wallick Communities provides property management, development, construction, and asset management for affordable housing and senior living communities. The company was founded in 1966 and is headquartered in New Albany, Ohio |
|||||
| Ransomware | Cooperativa de Ahorro y Crédito Ahorrocoop Ltda id6391 View details | Chile | Finance / Legal / Insurance | ||
|
Cooperativa de Ahorro y Crédito Ahorrocoop Ltda is a financial services company. The company employs 51-100 people, and revenue ranges from $ 10 to $25 million. The company's headquarters are located at 1421 5 Oriente, Talca, Maule, Chile |
|||||
| Ransomware | Sonda (Duplicate with update) id6358 View details | Chile | Telecommunications | ||
|
Sonda, This is a Chilean multinational IT company headquartered in Santiago we hacked last month. But it's network is still vulnerable and we hacked into company again in 2023-05-04. There is proof image below. More than 4TB of data is published on telegram channel today. Everyone can access & download it's data. We recommend companies not to use Sonda IT support. |
|||||
| Ransomware | The Crown Princess Mary Cancer Centre id6334 View details | Australia | Communication / Marketing | ||
|
Westmead's service has been operating since 1994 at 75 Railway St, Mount Druitt, New South Wales, 2770, Australia and sees more than 500 families a year. The service is part of the Sydney West Cancer Network and has outreach services to Nepean Blue Mountains and Wagga/Bathurst/Orange (by Telehealth). |
|||||
| Ransomware | Alto Calore Servizi S.p.A. id6305 View details | Italy | Communication / Marketing | ||
|
Alto Calore Servizi S.p.A., abbreviated ACS, was established on March 13, 2003. Alto Valore Servizi is a joint stock company consisting of 126 shareholders: 125 municipalities in the province of Avellino and Benevento and the administration of the province of Avellino. Alto Calore Servizi works in the field of collection and distribution of drinking water, sewerage and wastewater treatment. |
|||||
| Ransomware | Polat Yol Yap id6304 View details | Construction / Real Estate | |||
|
Polat Yol Yap is a company that operates in the construction industry, founded in 1975. The company employs from 2,001 to 5,000 people, and revenue ranges from $ 500 million to $1 billion. The company's headquarters is located in Cafe, Istanbul, Turkey. |
|||||
| Ransomware | Bevan Group id6260 View details | Communication / Marketing | |||
|
Founded in 1976, the Bevan Group company is a leading British supplier of commercial vehicle bodies, producing more than 60 commercial vehicle bodies every week. Bevan Group consists of five main companies: Busan Car Bodies, A&R Vehicle Services, After care Response, Graphics Depot and Supertruses. |
|||||
| Ransomware | Magnolia Care Center id6233 View details | United States | Public Sector | ||
|
Magnolia Care Center ~ A Veteran's Home~ is a Residential Veterans Personal Care Facility and Adult Day Care Center. Located at 16950 Florida Blvd, Baton Rouge, Louisiana, 70819, United States |
|||||
| Ransomware | Bentham & Holroyd Ltd id6221 View details | Manufacturing / Engineering | |||
|
Bentham & Holroyd Ltd is an engineering firm founded in 1830, subcontracted, based in Bradford, West Yorkshire, specializing in the production of precision components for the oil and gas industry, as well as offering a variety of services in CNC turning and manual turning, CNC milling, waterjet cutting and welding. |
|||||
| Ransomware | WestcoastSmile Dental Studio id6208 View details | Jordan | Healthcare / Pharma | ||
|
WestcoastSmile Kitsilano Dental Studio was established more than 20 years ago at 1-1874 W 1st Ave, Vancouver, British Columbia, V6J 1G5, Canada. The head is Dr. Jeffrey Jordan, who has been specializing in the dental field of medical activity for more than 30 years |
|||||
| Ransomware | Uniondale School District id6141 View details | Education | |||
|
Uniondale School District is a district located in Uniondale, NY. They are comprised of 9 different schools around the area: California Avenue School, Grand Avenue School, Northern Parkway School, Smith Street School, Walnut Street School, Lawrence Road Middle School, Turtle Hook Middle School, Uniondale High School and Cornelius Court School. As of the 2023 school year , 6523 students are enrolled in Uniondale School District. |
|||||
| Ransomware | Allimand, France id6132 View details | France | Communication / Marketing | ||
|
Founded in 1850 in France, Allimand is a world leader in the development and production of machines for the production of paper, cardboard and fiber mats with high added value.On average, 85% of sales are exported, employees and representatives of Allimand accompany their customers in 40 countries around the world. |
|||||
| Ransomware | Scantibodies Laboratory, Inc. id6064 View details | Communication / Marketing | |||
|
Scantibodies Laboratory, Inc. (SLI) founded in 1976 and headquartered in Santee, California, develops and manufactures medical diagnostic products. The company offers products such as antigens, antibodies, blockers, calibrators, plasma and diagnostic kits. SLI sells its products worldwide. |
|||||
| Ransomware | Atlantic International University id6045 View details | United States | Education | ||
|
Atlantic International University, V. ("AIA") is a private commercial distance learning university based in Honolulu, Hawaii, was founded in December 1998 as Atlantic University. Despite the fact that the AIA is located in Hawaii, it is not accredited by a recognized accreditation agency of the United States, and therefore was prosecuted for providing false information to its clients about the accreditation of an educational institution. |
|||||
| Ransomware | Open University of Cyprus id6034 View details | Cyprus | Education | ||
|
The Open University of Cyprus (OUC) was established in 2002 and, as a public university, specializes in distance education, helping to bring Cyprus closer to achieving its strategic goal: to become a regional educational and research center and a center for international scientists and students in the Eastern Mediterranean basin. At the moment , more than 4,000 students are studying at the university , and the university is also engaged in scientific research activities |
|||||
| Ransomware | Sonda id6002 View details | Chile | IT | ||
|
SONDA, a Chilean multinational IT company headquartered in Santiago, is the leader of digital transformation in the region with more than 13,000 employees, presence in 11 countries and implementation of solutions in more than 3,000 cities.It is the biggest in the sector of Information technology in Latin America. |
|||||
| Ransomware | Arandell Corp id5991 View details | Communication / Marketing | |||
|
Founded in 1922, Arandell provides premedia, catalog printing, mailing, distribution, list management, database marketing, mobile solutions, logistics and consulting services to its partners in the retail and direct mail catalog markets. |
|||||
| Ransomware | Gujarat Mineral id5877 View details | India | Manufacturing / Engineering | ||
|
Gujarat Mineral Development Corporation Limited (GMDC) is a large Indian state-owned mining and brown coal company based in Ahmedabad.GMDC was founded in 1963, its product range includes basic energy minerals such as brown coal, base metals and industrial minerals such as bauxite and fluorspar, as well as participates in the business related to oil refining. |
|||||
| Ransomware | Atlas Security id5804 View details | South Africa | Communication / Marketing | ||
|
Atlas Security is the leading armed response company in Nelson Mandela Bay and Alexandria . The company has more than 150 qualified armed response officers, the largest fleet of armed response vehicles. Atlas Security's client base includes more than 30,000 controlled secure premises in the Eastern Cape Province, including large corporate clients. |
|||||
| Ransomware | Law Firm Vazquez Nava Consultores y Abogados, S.C id5770 View details | Mexico | Finance / Legal / Insurance | ||
|
The Firm Vazquez Nava Consultores y Abogados, S.C. was founded in Mexico City in January 1995 by a group of professionals with a broad experience in fields such as Economics, Law, Administration and Engineering. Since its foundation, the Firm has actively participated in the development and structuring of some of the most important projects in Mexico, playing an important role in implementing the best practices for transparency, accountability and anti-corruption measures. |
|||||
| Ransomware | National Institute of Ocean Technology id5746 View details | India | IT | ||
|
The National Institute of Ocean Technology (NIOT) was established in November 1993 as an autonomous society under the Ministry of Earth Sciences in India. NIOT is managed by a Governing Council and is headed by a director. The institute is based in Chennai. The major aim of starting NIOT was to develop reliable indigenous technologies to solve various engineering problems associated with harvesting of non-living and living resources in India's exclusive economic zone, which is about two-thirds of the land area of India. |
|||||
| Ransomware | LLPGroup id5701 View details | Czechia | Services | ||
|
LLP Group is an international software services group founded in 1992 in the Czech Republic with offices in Western, Central and Eastern Europe, North America and Latin America, providing software consulting services, software development, ERP implementation and business process consulting. The company has 30 years of experience in consulting, developing and implementing systems in more than 70 countries around the world. |
|||||
| Ransomware | Bishop Luffa School id5690 View details | United Kingdom | Education | ||
|
Bishop Luffa School, named after a former Bishop of Chichester, Ralph de Luffa, is a co-educational Church of England secondary school located in Chichester, West Sussex, England. On December 1, 2013, the school successfully received the status of an academy. At the moment, 1517 students aged 11 to 18 are studying. |
|||||
| Ransomware | Garbarino SAICeI id5634 View details | Argentina | Hospitality / Food & Beverage / Tourism | ||
|
Garbarino, headquartered in Argentina, founded in 1951, is a retail company offering a wide range of products, including technology, appliances, furniture, sportswear, tools. Garbarino offers the most prestigious brands with over 5000 items. |
|||||
| Ransomware | National Business Furniture id5633 View details | Services | |||
|
National Business Furniture (NBF), founded in 1975, is an office furniture manufacturer headquartered in Milwaukee, Wisconsin. The company has additional offices in New York, Chicago, Los Angeles, Atlanta, Dallas, Phoenix and Seattle. In 2006, NBF was acquired by TAKKT AG, a leading direct marketing specialist for B2B business equipment in Europe and North America. |
|||||
| Ransomware | Minneapolis Public Schools id5590 View details | — | |||
|
Minneapolis Public Schools (MPS) or Special School District Number 1 is a public school district serving students in pre-kindergarten through twelfth grade from Minneapolis, Minnesota. Minneapolis Public Schools enrolls 36,370 students in public primary and secondary schools. The district administers about one hundred public schools including forty-five elementary schools, seven middle schools, seven high schools, eight special education schools, eight alternative schools, nineteen contract alternative schools, and five charter schools. With authority granted by the state legislature, the school board makes policy, selects the superintendent, and oversees the district's budget, curriculum, personnel, and facilities. Students speak ninety different languages at home and most school communications are printed in English, Hmong, Spanish, and Somali. |
|||||
| Ransomware | Minneapolis Public Schools id32037 View details | — | |||
|
Minneapolis Public Schools (MPS) or Special School District Number 1 is a public school district serving students in pre-kindergarten through twelfth grade from Minneapolis, Minnesota. Minneapolis Public Schools enrolls 36,370 students in public primary and secondary schools. The district administers about one hundred public schools including forty-five elementary schools, seven middle schools, seven high schools, eight special education schools, eight alternative schools, nineteen contract alternative schools, and five charter schools. With authority granted by the state legislature, the school board makes policy, selects the superintendent, and oversees the district's budget, curriculum, personnel, and facilities. Students speak ninety different languages at home and most school communications are printed in English, Hmong, Spanish, and Somali. |
|||||
| Ransomware | The Institute of Space Technology id5584 View details | Pakistan | — | ||
|
The Institute of Space Technology (also known as IST) is a public university located in Islamabad, Pakistan. IST space program aims at designing, building, launching and succesfully operating the Pico-Satellite standard CubeSat. The program is led by Communication Systems Engineering (CSE). Established in 2002 under the auspices of the Pakistan National Space Agency. IST offers a wide array of undergraduate and graduate degrees in partnership of Beihang University and University of Surrey. |
|||||