Ransomware dossier

Medusa

RaaS with a public leak blog and a countdown-timer extortion model across many sectors.

Claimed victims

181

Top region

—

Top sector

—

Suspected origin

Russia

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2024-03-26Autorità di Sistema Portuale del Mar Tirreno Settentrionale It——
2024-03-26Elior UK——
2024-03-26Romark Laboratories——
2024-03-26Accipiter Capital Management, LLC——
2024-03-26Urban Strategies——
2024-03-26Kenneth Young Center——
2024-03-26Suburban Surgical Care Specialists——
2024-03-26Henry County, Illinois——
2024-03-26Regina Dental Group——
2024-03-26Impac Mortgage Holdings——

Suspected origin

Russia — Russian-speaking RaaS (OSINT). Attribution reflects open-source consensus, not certainty.

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups