Medusa
RaaS with a public leak blog and a countdown-timer extortion model across many sectors.
Claimed victims
181
Top region
—
Top sector
—
Suspected origin
Russia
Latest claimed victims
Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.
| Date | Organisation (claimed) | Sector | Country |
|---|---|---|---|
| 2024-03-26 | Autorità di Sistema Portuale del Mar Tirreno Settentrionale It | — | — |
| 2024-03-26 | Elior UK | — | — |
| 2024-03-26 | Romark Laboratories | — | — |
| 2024-03-26 | Accipiter Capital Management, LLC | — | — |
| 2024-03-26 | Urban Strategies | — | — |
| 2024-03-26 | Kenneth Young Center | — | — |
| 2024-03-26 | Suburban Surgical Care Specialists | — | — |
| 2024-03-26 | Henry County, Illinois | — | — |
| 2024-03-26 | Regina Dental Group | — | — |
| 2024-03-26 | Impac Mortgage Holdings | — | — |
Suspected origin
Russia — Russian-speaking RaaS (OSINT). Attribution reflects open-source consensus, not certainty.
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveDefender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.