Quick Summary
AllegedExecutive Summary
Seznam, a prominent technology company operating the popular seznam[.]cz domain in the Czech Republic, has been listed as a victim by the MedusaLocker ransomware group. The claim was made public on September 23, 2026, and was identified through SOCRadar’s Dark Web Monitoring service. Seznam is a major internet platform in the Czech Republic, offering services such as search, email, news, maps, and classifieds, reaching a substantial portion of the Czech user base. This incident represents MedusaLocker’s most significant claim within the technology sector during the observed monitoring period, as most of their recent targets have been considerably smaller in scale. The nature of Seznam’s extensive digital footprint and user engagement likely made it an attractive target for ransomware operations seeking widespread impact. In the 60 days preceding this listing, MedusaLocker had claimed 18 other victims. The group primarily targets the Manufacturing and Technology sectors, with a geographical focus on France, India, and the United States. Seznam’s listing deviates from the group’s typical geographic targeting pattern, as the Czech Republic is not frequently featured in their recent victim lists. This suggests that the claim might be opportunistic rather than part of a targeted campaign specifically focused on the Czech market.
Technical Analysis
The SOCRadar Dark Web Monitoring service queried the domain seznam[.]cz, revealing a significant exposure of 25 records dated between 2024 and 2026. Of these, 17 were categorized as INTERNAL_AUTH_EMPLOYEE (Category A), meaning they involved corporate @seznam.cz email addresses paired with seznam[.]cz URLs and third-party services, including the Cisco identity portal (id.cisco.com). An additional two records were classified as INTERNAL_AUTH_EXTERNAL_USER. The presence of Cisco SSO credentials is particularly noteworthy, as it indicates potential employee access to enterprise networking infrastructure, a common target for initial access by ransomware groups. The extensive nature of the Category-A records, with 17 instances spanning two years, suggests persistent credential harvesting rather than a isolated, one-time event. Such prolonged exposure of internal authentication credentials, especially those linked to enterprise access points like the Cisco identity portal, creates a viable pathway for attackers. This information could be leveraged by threat actors like MedusaLocker to gain unauthorized access, move laterally within the network, and deploy ransomware. The observed stealer-log exposure is consistent with the precursor activity seen in other MedusaLocker incidents. Organizations experiencing such credential exposure are strongly advised to undertake immediate and comprehensive security measures. This includes emergency credential rotation for all @seznam.cz accounts, a thorough review of sign-in logs for both Cisco and internal portals to detect any anomalous activity, and proactive threat hunting to identify indicators of any prior unauthorized access. These actions are crucial regardless of whether MedusaLocker directly utilized these specific compromised credentials, as their existence points to a general vulnerability.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.