Medusa

Quiet since May 11, 2026
540 victims named on the leak site
0 in the last 30 days
69 in the last 12 months
Feb 2022 first victim we recorded
May 11, 2026 most recent victim posted
10 leak sites tracked

Data as of August 16, 2026.

Credential exposure before the attack

30.9% of Medusa victims whose domain we can identify (167 of 540) had employee credentials leak in the 12 months before Medusa named them as a victim.

We don't know whether any of these credentials were how Medusa gained initial access.

What industries Medusa targets

Sector identified for 315 of 540 victims.

Manufacturing52
Healthcare47
Education42
Financial Services32
Construction23
Technology20
Retail17
Logistics14

Where the victims are located

Country identified for 217 of 540 victims.

United States66
United Kingdom23
Canada18
Italy13
Brazil12
Australia12
Germany9
France9

Most recent Medusa victims

VictimSectorCountryPosted
Walman Optical walman.comNot identifiedUnited StatesApr 27, 2026
NEMR nemr.netTelecommunicationsUnited StatesApr 14, 2026
TouchSource touchsource.comTechnologyUnited StatesApr 6, 2026
Big Thumb schlamstone.comNot identifiedUnited StatesMar 30, 2026
Cape May County New Jersey capemaycountynj.govGovernmentUnited StatesMar 26, 2026
Lorain County Community College lccc.eduEducationUnited StatesMar 26, 2026
LiveCH livech.comNot identifiedSwitzerlandMar 26, 2026
Bonanza Casino bonanzacasino.comNot identifiedNetherlandsMar 18, 2026
Cape May County capemaycountynj.govGovernmentUnited StatesMar 18, 2026
Lehigh Carbon Community College lccc.eduEducationUnited StatesMar 18, 2026
Passaic County passaiccountynj.orgGovernmentUnited StatesMar 18, 2026
University of Mississippi Medical Center umc.eduHealthcareUnited StatesMar 12, 2026
Acme Trucking acmetruck.comLogisticsUnited StatesMar 3, 2026
IPG ipgltd.comFinancial ServicesUnited KingdomMar 3, 2026
Shaft Drillers shaftdrillers.comNot identifiedUnited StatesMar 3, 2026
Amevida amevida.deNot identifiedGermanyFeb 26, 2026
Chartre Consulting chartre.comRetailUnited StatesFeb 26, 2026
ToolPartsPro toolpartspro.comRetailUnited StatesFeb 26, 2026
Aramsco aramsco.comNot identifiedUnited StatesFeb 23, 2026
Colonial Van Lines colonialvanlines.comNot identifiedUnited StatesFeb 23, 2026

Showing the 20 most recent of 540. Browse recent data breaches for more.

Medusa leak sites

Addresses we've seen Medusa publish victims from. Any .onion address needs the Tor Browser.

  • xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion
  • medusaxko7jxtrojdkxo66j7ck4q5tgktf7uqsqyfry4ebnxlcbkccyd.onion
  • cx5u7zxbvrfyoj6ughw76oa264ucuuizmmzypwum6ear7pct4yc723qd.onion
  • s7lmmhlt3iwnwirxvgjidl6omcblvw2rg75txjfduy73kx5brlmiulad.onion
  • z6wkgghtoawog5noty5nxulmmt2zs7c3yvwr22v4czbffdoly2kl4uad.onion
  • alphvmmm27o3abo3r2mlmjrpdmzle3rykajqc5xsj7j7ejksbpsa36ad.onion
  • 7aqabivkwmpvjkyefonf3gpy5gsubopqni7kcirsrq3pflckxq5zz4id.onion
  • wtyafjyhwqrgo4a45wdvvwhen3cx4euie73qvlhkhvlrexljoyuklaad.onion
  • lockbitcuo23q7qrymbk6dsp2sadltspjvjxgcyp4elbnbr6tcnwq7qd.onion
  • qkzxzeabulbbaevqkoy2ew4nukakbi4etnnkcyo3avhwu7ih7cql4gyd.onion

Medusa questions

Is Medusa still active?

It's gone quiet. The last victim we recorded was May 11, 2026, and nothing has appeared since. Groups do go quiet and come back, so we're still watching.

How many victims has Medusa claimed?

Medusa has named 540 victims on its leak site since we started tracking it. That counts organizations, not leaked files. A single victim often accounts for thousands of published files. 69 of them were posted in the last 12 months.

When did Medusa first appear?

The first victim we recorded for Medusa was posted on February 14, 2022. That's when the group entered our collection, which isn't necessarily when it started operating.

Which sectors does Medusa target?

Manufacturing accounts for the most victims we can classify, with 52. Healthcare follows at 47. We could identify a sector for 315 of 540 victims, so treat this as the shape of the targeting rather than a full census.

Has Medusa already got your credentials?

Check whether your employees' logins have leaked on the dark web before they're exploited.

Check your exposure →

Continuous dark web monitoring alerts you when your company's data shows up, whether that's employee credentials or files published after an attack.