Quick Summary
AllegedExecutive Summary
MedusaLocker has claimed responsibility for a data breach involving NSW Health, the primary government healthcare authority for New South Wales, Australia. The listing appeared on the ransomware group’s dark web portal on August 27, 2026, and was identified by SOCRadar’s Dark Web Monitoring service. NSW Health is a critical public service, responsible for administering a vast network of hospitals, community health facilities, and population health programs that serve over eight million individuals. This scale of operation and the sensitive nature of health data make it a high-value target for ransomware and extortion actors. The MedusaLocker group has been actively targeting organizations across various sectors. In the 60 days preceding this listing, the group claimed victims such as Qualisteel (a steel manufacturer), Hungry Lion (a fast-food chain), Servifruit (a Mexican produce distributor), and Jgsee (a Thai research university). While the group has shown no hesitation in targeting private sector entities, the inclusion of a major public healthcare system like NSW Health highlights their willingness to pursue high-consequence targets, regardless of whether they are public or private. NSW Health represents a significantly more high-profile and impactful target compared to its previous victims.
Technical Analysis
SOCRadar’s threat intelligence platform detected 23 employee credentials associated with the domain health[.]nsw[.]gov[.]au. A significant portion of these records were for Microsoft 365 (login[.]microsoftonline[.]com), indicating potential direct access to the NSW Health Microsoft 365 tenant. The telemetry also identified additional credential records targeting internal NSW Health single sign-on (SSO) endpoints. The observed credentials were fresh, with an exposure window from August 10 to August 27, 2026, meaning they were actively in use shortly before or around the time of the ransomware group’s listing. This compressed exposure-to-incident timeline is highly indicative of attacks that leverage recently compromised credentials, often harvested from stealer-log malware. The correlation between the active Microsoft 365 credentials, internal SSO access, and the timing of the MedusaLocker listing presents a strong link between credential exposure and potential intrusion. For an organization of NSW Health’s size and importance, a compromise could have severe ramifications, including mandatory notification obligations under Australia’s Privacy Act and significant disruption to patient care continuity. Given the findings, continued dark web monitoring for any further mentions or data associated with NSW Health is recommended. Organizations should also conduct thorough credential hygiene checks, including password rotation and reviewing multi-factor authentication (MFA) configurations across all critical systems. Monitoring of Microsoft 365, VPNs, and other remote access portals for anomalous activity should be intensified.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.