Quick Summary
AllegedExecutive Summary
Twal Family IT Lab, a company operating within the Technology sector and based in Canada, has been identified as a victim by the medusalocker ransomware group. The listing appeared on the group’s dark web portal on August 16, 2026, and was detected by SOCRadar’s Dark Web Monitoring service. This incident places Twal Family IT Lab among a growing number of entities recently targeted by medusalocker, underscoring the group’s persistent and widespread activity across various industries and geographical locations. In the 60 days preceding this listing, medusalocker claimed six other victims. The ransomware group exhibits a clear preference for targeting the Technology, Transportation, and Manufacturing sectors, with a significant concentration of victims located in Canada, South Africa, and France. Recent incidents involving organizations such as Idex Group, ZT Systems, Thecourierguy, and Bija Industrie highlight medusalocker’s broad operational reach. The inclusion of Twal Family IT Lab aligns with the group’s established pattern of targeting technology companies.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry for twalfamily.com yielded no direct records within the queried dataset. It is important to note that a null result does not definitively indicate that the organization is unaffected. The sample data may have been limited or paginated, and it is possible that credentials associated with Twal Family IT Lab exist under alternate corporate domains or were accessed using personal email aliases utilized by employees. Therefore, threat intelligence teams should not interpret this absence of evidence as confirmation of no compromise. For ransomware operations, including those attributed to groups like medusalocker, infostealer-harvested credentials are a frequently observed method for initial access. Threat actors or initial access brokers typically acquire credential logs from underground marketplaces, validate them, and then use these to gain access to systems such as Microsoft 365, VPNs, or remote-access portals, subsequently deploying ransomware. The lack of findings in this particular query does not preclude such a scenario, as credentials might have been present in datasets not covered by this search, rotated before indexing, or harvested via personal email accounts. The absence of identified credentials in the queried telemetry does not rule out the possibility of credential compromise supporting a ransomware attack. Infostealer logs are a common vector for initial access, often sourced from the dark web and used to compromise corporate accounts, VPNs, or remote-access portals. Given this, CTI teams should continue monitoring dark web forums and stealer logs, and conduct proactive credential hygiene checks, including password rotation and multi-factor authentication reviews for Microsoft 365, VPNs, and other remote access solutions.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.