Licindia Data Breach

Alleged

Ransomware claim involving Licindia.

Published: Sep 2, 2026 MedusaLocker
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Licindia
Industry
Services
Threat Actor
MedusaLocker
Date of Incident
Sep 2, 2026

Executive Summary

Licindia, a company based in India operating within the services sector, was reportedly targeted by the MedusaLocker ransomware group. The group listed Licindia on its dark web portal on September 2, 2026, as identified by SOCRadar’s Dark Web Monitoring service. While the claim has been made, it has not been independently verified. The services sector can be an attractive target for ransomware groups due to the critical nature of the operations and the potential for business disruption. In the 60 days leading up to this listing, MedusaLocker claimed approximately 13 victims across diverse industries including Manufacturing, Retail & E-Commerce, and Agriculture and Food Production. Their victimology geographically spans countries such as Canada, India, and the United States. Recent notable victims include Lawter (United States, Manufacturing), Hungry Lion (Ghana, Retail & E-Commerce), Thecourierguy (South Africa, Transportation), and Servifruit (Mexico, Agriculture and Food Production). Licindia represents the most recent victim listed from India within this timeframe, aligning with MedusaLocker’s pattern of targeting a geographically diverse range of organizations.

Technical Analysis

SOCRadar’s stealer-log telemetry data revealed a significant exposure for the domain licindia[.]com. The analysis uncovered 16 employee credentials categorized as category A, meaning they were found on organization-controlled systems. These credentials were predominantly linked to mail infrastructure, including webmail and email portals, as well as a sales platform and an internal e-business system. Notably, one credential involved a third-party Single Sign-On (SSO) identity service accessed via a corporate account, which presents a potential vector for lateral movement into downstream Software as a Service (SaaS) tenants. An additional three records, classified as category C, indicated corporate users on third-party services, suggesting potential workstation compromise. The compromised credentials span the period from August 27 to September 2, 2026. A critical observation was that one record had an insert date more than 90 days prior to its log date, indicating that these credentials had been persisted for an extended period, potentially well before the immediate incident window. The affected credentials appear to have remained unrotated throughout this timeframe. This long-standing credential exposure could provide threat actors with ample opportunity for reconnaissance, including monitoring outbound communications, mapping internal systems, and identifying high-value targets before deploying a ransomware payload. The presence of a third-party SSO record further complicates the security posture, as it introduces cross-platform exposure that might not be detected by standard email log reviews alone. MedusaLocker’s typical operational patterns are consistent with this type of access profile. – Force credential rotation across all accounts identified in the sample. – Audit webmail and email portal access logs across the August–September window and further back given the 90-day persistence indicator. – Investigate the third-party SSO identity service record for unauthorized downstream tenant access. – Review the sales platform and e-business system for unauthorized data export activity. – Expand monitoring scope to cover personal email aliases used on corporate devices.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.