Ransomware

Medusa Claims Responsibility for Attack on Corporación Digitel C.A.

In January 2024, the Venezuelan telecommunications provider Corporación Digitel C.A. suffered a ransomware attack orchestrated by the threat actor Medusa. The attackers breached the company’s servers on January 30, 2024, and extracted confidential information, including employee lists, identification documents, emails, and confidential financial records. Medusa demanded a ransom of $5,000,000 to prevent the disclosure of the stolen data. After the ransom deadline expired, the threat actor published the compromised data on its dark web leak site, Medusa Blog, on February 12, 2024.

Overview

Missing evidence

The original Medusa onion leak page is not publicly accessible via standard web browsing.No publicly available official statement from Digitel was found confirming the ransomware incident, the exact types of data affected, or the ultimate impact.

Impact details

Digitel data was published following the Medusa ransomware claim. Public sources cite an analysis by VE sin Filtro revealing 12.6 GB of unique data, including first names, last names, ID numbers, dates of birth, financial documents, reports, invoices, contracts, subscriber agreements, and employee data. Digitel acknowledged the incident, stated that it did not affect normal service operations, and initially denied any breach of user data.

namesID numbersdates of birthemployee datafinancial documentsinvoices

Classification & severity

Category
Malicious code
Subtype
Ransomware
Confidence
High

Several sources have reported on the Medusa ransomware, the ransom demand, and the subsequent release of the data.

Severity assessment

High
Information impact
Personal data
Critical service
Potential
Public confidence
Moderate
Recoverability
Extended
Data exfiltration· Confirmed ConfidentialityIntegrityAvailability

Timeline

Claim

Medusa listed Corporacion Digitel C.A. as an alleged victim.

Evidence & sources

2 sources