Medusa
Medusa is a data-theft and double-extortion group that operates a dedicated leak site; it should not be confused with MedusaLocker, a separate family of malware.
- Incidents
- 2
- High impact
- 1
- First seen
- Feb 2, 2024
- Latest seen
- Jun 27, 2024
Linked incidents
Medusa Group (allegedly) attacks Farmatodo, leaving the chain without electronic payment options
On June 27, 2024, the pharmacy and retail chain Farmatodo suffered a cyberattack that paralyzed its electronic payment systems nationwide—including integrated point-of-sale, mobile payment, self-checkout, and delivery payment—forcing the company to operate on cash only for several hours. Security experts attributed the incident to the Medusa group, the same actor linked to previous attacks against Digitel and Banco de Venezuela, which publicly mocked Farmatodo on X with the message “Farmatodo, is everything okay?” The company did not issue an official statement regarding the cause of the incident.
Medusa Claims Responsibility for Attack on Corporación Digitel C.A.
In January 2024, the Venezuelan telecommunications provider Corporación Digitel C.A. suffered a ransomware attack orchestrated by the threat actor Medusa. The attackers breached the company’s servers on January 30, 2024, and extracted confidential information, including employee lists, identification documents, emails, and confidential financial records. Medusa demanded a ransom of $5,000,000 to prevent the disclosure of the stolen data. After the ransom deadline expired, the threat actor published the compromised data on its dark web leak site, Medusa Blog, on February 12, 2024.