Quick Summary
AllegedExecutive Summary
MedusaLocker added Rueegseggerag, a Swiss company, to its dark web leak site on October 5, 2026. The group claims to have accessed corporate systems and is threatening to publish data. This incident is consistent with MedusaLocker’s ongoing campaign, which has targeted numerous victims across Europe and North America. Switzerland’s concentration of high-value firms makes it a frequent target for such attacks. In the past 60 days, MedusaLocker has claimed 25 victims, with a notable focus on the manufacturing and technology sectors in Spain, Canada, and France. Rueegseggerag joins a list of previously claimed victims, including Aokkef, Jgsee, Millensys, and Premiumfruits. MedusaLocker operates as a Ransomware-as-a-Service (RaaS) platform, meaning its affiliates may employ varied techniques even while using the same ransomware.
Technical Analysis
SOCRadar’s query for rueegseggerag[.]ch returned no results. This indicates that no stealer log records were found for the specified domain. However, this absence of evidence does not confirm that no compromise occurred. Credentials may exist under related corporate domains or within data feeds not captured by this specific query. It is more probable that MedusaLocker affiliates utilized alternative initial access vectors. These could include phishing campaigns, exploitation of unpatched public-facing applications, or the purchase of compromised access from underground marketplaces. The group employs a double-extortion model, which involves both encrypting victim data and exfiltrating sensitive information. Worth noting for Swiss organizations like Rueegseggerag, MedusaLocker’s double-extortion tactic means that any sensitive data, including client information, financial records, or proprietary data, is potentially exfiltrated and may be published on the dark web. This scenario triggers breach notification obligations under Switzerland’s nDSG data protection law and GDPR. Organizations in such situations should engage a certified incident response team immediately.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.