Medusa Claims Responsibility for Attack on Corporación Digitel C.A.
In January 2024, the Venezuelan telecommunications provider Corporación Digitel C.A. suffered a ransomware attack orchestrated by the threat actor Medusa. The attackers breached the company’s servers on January 30, 2024, and extracted confidential information, including employee lists, identification documents, emails, and confidential financial records. Medusa demanded a ransom of $5,000,000 to prevent the disclosure of the stolen data. After the ransom deadline expired, the threat actor published the compromised data on its dark web leak site, Medusa Blog, on February 12, 2024.
Overview
Missing evidence
Impact details
Digitel data was published following the Medusa ransomware claim. Public sources cite an analysis by VE sin Filtro revealing 12.6 GB of unique data, including first names, last names, ID numbers, dates of birth, financial documents, reports, invoices, contracts, subscriber agreements, and employee data. Digitel acknowledged the incident, stated that it did not affect normal service operations, and initially denied any breach of user data.
Classification & severity
- Category
- Malicious code
- Subtype
- Ransomware
- Confidence
- High
Several sources have reported on the Medusa ransomware, the ransom demand, and the subsequent release of the data.
Severity assessment
High- Information impact
- Personal data
- Critical service
- Potential
- Public confidence
- Moderate
- Recoverability
- Extended
Timeline
Medusa listed Corporacion Digitel C.A. as an alleged victim.