Hungry Lion Data Breach

Alleged

Ransomware claim involving Hungry Lion

Published: Aug 27, 2026 MedusaLocker
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Hungry Lion
Industry
Retail
Threat Actor
MedusaLocker
Date of Incident
Aug 27, 2026

Executive Summary

Hungry Lion, a prominent fast-food chain with extensive franchise operations across sub-Saharan Africa, has been listed as a victim by the MedusaLocker ransomware group. The listing was identified on August 27, 2026, through SOCRadar’s Dark Web Monitoring service. The company’s position as a consumer-facing entity with an active online ordering platform and loyalty program, which aggregates significant customer personal data, makes it a potentially attractive target for ransomware actors seeking to exploit sensitive information. MedusaLocker has been actively targeting various sectors, including healthcare, manufacturing, and the public sector, over the past 60 days. Notable recent victims attributed to this group include NSW Health in Australia, Qualisteel, and Servifruit. The targeting of Hungry Lion, a retail company heavily reliant on customer engagement and data, presents a slightly different profile compared to the typically more industrial or public sector targets frequently associated with MedusaLocker’s recent activities.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed 23 records associated with the domain hungrylion[.]co[.]za. Of these records, 13 were identified as customer accounts, and an additional 10 consisted of numerical IDs with an unclear profile type. All identified records relate to the company’s consumer-facing web self-service portals. The data freshness window spans from October 2025 to July 2026, indicating a continuous exposure of customer data on Hungry Lion’s web infrastructure for approximately nine months. This observed telemetry indicates a Customer Account Takeover (ATO) profile rather than evidence of a direct corporate intrusion. The exposed credentials are concentrated on customer-facing portals, suggesting the compromise originated from consumer devices rather than corporate endpoints. While this does not directly point to a corporate network compromise for ransomware deployment, the sustained exposure of customer data is a significant security concern. It necessitates immediate assessment for customer notification obligations, particularly under South African data protection law (POPIA), and a thorough review of web portal security. The identified exposure warrants a comprehensive security review of the hungrylion[.]co[.]za web portal and its associated ordering infrastructure. Organizations should also continue monitoring for any potential data publication by the MedusaLocker group, as they typically release stolen data if ransom demands are not met.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.