Share this article on:
The infamous Medusa ransomware gang has claimed an attack on a US Federal Credit Union, leading to the leak of personal and financial information.
The US 1364 Federal Credit Union is a non-profit financial organisation that provides a number of financial services, such as loans, investments, savings, credit and debit cards, and online banking.
The organisation was listed on Medusa’s dark web leak site yesterday (7 March), with the threat group claiming to have accessed its systems and stolen data, providing screenshots to back its claims.
According to the VenariX threat feed observed by Cyber Daily, potentially exposed data is substantial, including first and last names, dates of birth, ID numbers and cards, passport numbers and screenshots, driver’s license numbers and cards, confidential business data, email addresses and bank account numbers.
While it has not shared all the data, on its leak site, it has provided screenshots of Indiana licenses and US passports, as well as financial documents of recent dates such as 1 January 2024.
It is also worth noting that the US 1364 Federal Credit Union suffered “technical difficulties in late February. While there is no guarantee that the incidents are connected, it could mark the date of Medusa’s access.
WE ARE CURRENTLY EXPERIENCING TECHNICAL DIFFICUTIES. WE APPRECIATE YOUR PATIENCE AS WE WORK TO RESOLVE THEM AND APOLOGIZE FOR ANY INCONVENIENCE.
— US Federal Credit Union #1364 (@usfederalcu) February 23, 2024
At this stage, the US 1364 Federal Credit Union has not issued a statement regarding the breach, nor is it clear whether or not ransom discussions have begun.
Medusa usually issues its victims a statement upon an attack being carried out, with a standardised message.
“While you are reading this message, it means all of your files and data has been ENCRYPTED by world’s strongest ransomware,” part of the message read.
“All files have been encrypted with new military-grade encryption algorithm and you cannot decrypt your files.
“But don’t worry, we can decrypt your files.”