Quick Summary
AllegedExecutive Summary
MedusaLocker claimed a ransomware incident against Millensys, an Egyptian company specializing in healthcare IT and medical software. The listing, dated October 5, 2026, indicates the threat actor’s intent to release stolen data. SOCRadar’s analysis uncovered a significant credential exposure, with 23 compromised records associated with millensys[.]com. This exposure window extends from February 2025 to October 2026, predating the leak-site listing by nearly two years. Millensys’s position as a provider of critical medical software makes it a valuable target, as a compromise could have far-reaching implications for its client base in the healthcare sector. In the preceding 60 days before this report, MedusaLocker claimed 25 victims, primarily targeting manufacturing and technology firms in Spain, Canada, and France. Notable recent victims include Seznam, Idex Group, Twal Family IT Lab, and Rueegseggerag. The group demonstrates a broad appetite for targets across various sectors, and healthcare IT aligns with its existing focus on technology, making Millensys a consistent fit for their operational pattern.
Technical Analysis
SOCRadar’s investigation into stealer log data revealed 23 compromised records pertaining to millensys[.]com. These records included 18 corporate credential logs, one business application credential, and four workstation compromise artifacts. The data spans from February 2025 to October 2026, indicating a prolonged period of exposure. The prevalence of corporate-level credential logs suggests a systematic effort to harvest employee domain credentials over nearly two years, with the discovery of workstation compromises in the more recent period. This extensive credential harvesting points towards a prolonged reconnaissance operation rather than a swift attack. Threat actors with this level of persistent access would have had ample opportunity to map Millensys’s internal network architecture, identify high-privilege accounts, and evaluate potential pathways into downstream healthcare provider networks through trusted update channels, VPN connections, or shared administrative credentials. Given this profile, Millensys should prioritize immediate notification to its healthcare provider clients about the incident and initiate a comprehensive supply chain impact assessment to ascertain any potential exposure of client environments.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.