MedusaLocker Claims Ohio Roofing Contractor
Ransomware tracker Ransomware.live lists Frisby Roofing/Frisby Construction LLC as a victim posted on the MedusaLocker leak site.
This entry is a victim listing from the Ransomware.live tracking platform, indicating that the MedusaLocker ransomware group has posted Frisby Roofing (Frisby Construction LLC), a small residential roofing contractor based in Milford, Ohio, on its extortion leak site. The listing aggregates publicly available business information about the victim (contact details, suppliers, payroll provider, legal filings) rather than technical intrusion details, exfiltrated data samples, or IOCs. No information is provided about the initial access vector, malware behavior, encryption specifics, or ransom demand.
For defenders, this is a low-detail victim notification typical of ransomware leak-site monitoring rather than a technical advisory. It confirms MedusaLocker's continued opportunistic targeting of small and mid-sized businesses across sectors, consistent with the group's historical pattern of targeting smaller organizations with likely weaker security postures rather than large enterprises. Organizations in similar verticals (construction, home services, small B2B contractors) should treat this as a reminder to review basic ransomware hygiene: RDP/VPN exposure, patching, backup integrity, and MFA on remote access and email accounts, since MedusaLocker has historically gained initial access via exposed RDP, phishing, and vulnerable VPN appliances in past campaigns reported elsewhere.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/RnJpc2J5IFJvb2ZpbmcgKEZyaXNieSBDb25zdHJ1Y3Rpb24gTExDKUBtZWR1c2Fsb2NrZXI=
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free