Jgsee (KMUTT) Data Breach

Alleged

MedusaLocker ransomware claim involving Jgsee (KMUTT).

Published: Aug 27, 2026 MedusaLocker
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Jgsee (KMUTT)
Industry
Education
Threat Actor
MedusaLocker
Date of Incident
Aug 27, 2026

Executive Summary

MedusaLocker has listed jgsee[.]kmutt[.]ac[.]th, representing the Joint Graduate School of Energy and Environment at King Mongkut’s University of Technology Thonburi (KMUTT) in Thailand, on its dark web portal. The listing, identified on August 27, 2026, by SOCRadar’s Dark Web Monitoring service, places an academic institution within the ransomware group’s targeting patterns. In the past 60 days, MedusaLocker has shown activity across healthcare, manufacturing, and public sector entities. Notable recent victims include Forces, Health (NSW Health), Qualisteel, and Hungry Lion. While the majority of these targets were a government health authority, a steel manufacturer, and a fast-food chain, Jgsee stands out as the sole research university targeted in this recent cohort. The group’s operational pattern indicates a broad, sector-agnostic approach to its attacks.

Technical Analysis

SOCRadar’s analysis of stealer-log telemetry revealed 22 records associated with jgsee[.]kmutt[.]ac[.]th. Of these, four records contained credentials belonging to employees or faculty, specifically targeting the institutional web infrastructure. The remaining 18 records pertained to external users, including students and visiting researchers, with credentials found for student portals and a WordPress admin interface. Notably, one credential was directly linked to a WordPress admin endpoint. The detected credentials have a freshness window ranging from February to July 2026. This exposure presents two distinct risk categories. The WordPress admin credential and the identified staff accounts pose a significant corporate intrusion risk. A compromised CMS admin account within university infrastructure could facilitate lateral movement into shared hosting environments and other connected institutional systems. Separately, the 18 records related to student-facing portals and interfaces create data protection obligations concerning the personal information of enrolled students and external researchers. The identified credential exposures, particularly the WordPress admin account, suggest a potential pathway for ransomware deployment. Compromised administrative credentials can grant threat actors access to critical systems, enabling them to deploy ransomware and exfiltrate sensitive data. Continued dark web monitoring, proactive credential hygiene checks, password rotation, and multi-factor authentication review are recommended actions.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.