Quick Summary
AllegedExecutive Summary
Thecourierguy, a company operating within the Transportation sector and based in South Africa, has been identified as a victim by the medusalocker ransomware group. The listing appeared on the group’s dark web portal on August 16, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. This incident places Thecourierguy among a growing number of entities targeted by medusalocker, which has maintained a consistent operational pace in recent months, impacting various sectors and regions. In the 60 days leading up to this listing, medusalocker claimed six other victims across its leak portal. The group primarily targets organizations in the Technology, Transportation, and Manufacturing sectors, with a significant concentration of victims in Canada, South Africa, and France. Recent listings for organizations such as Bija Industrie, Idex Group, All Parts Dry Cleaning, and Twal Family IT Lab highlight medusalocker’s broad reach. The inclusion of Thecourierguy aligns with the group’s established pattern of targeting entities within the transportation industry.
Technical Analysis
SOCRadar’s analysis of initial access vectors, by cross-referencing with stealer-log telemetry, returned no records for the domain thecourierguy.co.za within the queried dataset. However, a null result does not confirm the absence of a compromise. The paginated sample may not have encompassed all relevant logs, and credentials could potentially exist under alternate corporate domains or be associated with personal email aliases used by Thecourierguy employees. Consequently, CTI teams should not interpret a null query as definitive evidence that the organization is unaffected. For ransomware groups like medusalocker, compromised credentials harvested by infostealers represent a well-documented method for gaining initial access. Threat actors or initial access brokers often acquire recent credential logs from underground marketplaces, validate corporate account access, and then utilize these credentials to infiltrate systems such as Microsoft 365, VPNs, or remote-access portals before deploying ransomware. The absence of direct evidence in this specific query does not preclude this possibility, as credentials may have been circulated in data feeds not covered by the current dataset, rotated prior to indexing, or harvested using personal email addresses. Given these findings, CTI teams should prioritize continuous monitoring of dark web and stealer-log sources. Proactive credential hygiene checks, including password rotation and multi-factor authentication reviews for Microsoft 365, VPNs, and remote-access portals, are recommended actions. It is crucial to treat the absence of specific evidence as a call for increased vigilance rather than a confirmation of security.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.