# MedusaLocker lists ATCO Ltd as victim

Published: 2026-09-28 · Severity: elevated · Sectors: energy
Canonical: https://vorant.io/reports/3c5afd9d-8e60-5589-9d73-a6ca8b6c3440/medusalocker-lists-atco-ltd-as-victim

> Ransomware tracking site Ransomware.live logged ATCO Ltd as a victim claimed by the MedusaLocker ransomware group.

This entry is a victim listing from Ransomware.live, an aggregator that tracks claims made by ransomware groups on their leak sites. The record indicates that the MedusaLocker ransomware operation has listed ATCO Ltd as a victim. The article itself is sourced from a sponsored aggregator page and contains minimal technical detail beyond leak-site metadata: it references 10 third-party employee credentials and a leak screenshot, but provides no indication of compromised internal employees, compromised users, or exposed external attack surface counts.

No technical indicators of compromise, exploited vulnerabilities, malware samples, or TTPs are included in this listing. Defenders at ATCO Ltd or its supply chain/third parties should treat this as a notification of a claimed breach and pursue incident response, credential resets for any third-party accounts, and monitoring for data leaks, rather than acting on any technical detail, since none is provided here.

MedusaLocker is a known ransomware-as-a-service family that has been active since 2019, typically gaining initial access via exposed RDP, phishing, or vulnerability exploitation, followed by data exfiltration and encryption with double-extortion tactics. This specific listing does not describe the intrusion vector or timeline for the ATCO Ltd incident.

## Mentioned in this report

- Threat actors: medusalocker
- Malware: MedusaLocker

Source reporting: https://www.ransomware.live/id/QVRDTyBMdGRAbWVkdXNhbG9ja2Vy

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3c5afd9d-8e60-5589-9d73-a6ca8b6c3440/medusalocker-lists-atco-ltd-as-victim.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
