Medusa ransomware group claims attack on ARDEX Australia
- Organization
- ARDEX Australia
- Exploit
- Ransomware
- Industry
- Construction Products
ARDEX Australia, a manufacturer of tiling, flooring and waterproofing products based in Seven Hills, New South Wales, was named on the dark web leak site of the Medusa ransomware group in late January 2025. Cyber Daily reported the listing appeared on January 27, and the leak site tracker Ransomware.live logged the entry on January 29.
Medusa claimed to have stolen business documents containing both corporate and personal information. The group published a sample set that, according to Cyber Daily, included spreadsheets, product lists and pricing files, remuneration records, employment and position documents, internal policy files, emails and other material marked confidential. Personal details visible in the sample covered names, email addresses and phone numbers belonging to employees and clients.
In line with the group's usual double extortion approach, the listing carried a price. Medusa sought 300,000 US dollars either to delete the data or to sell it to a buyer, and offered to push back its publication countdown, set at roughly 22 days, for a further 10,000 dollars.
ARDEX Australia issued no public statement about the incident and did not respond to a request for comment from Cyber Daily. The scale and contents of the theft rest entirely on Medusa's own claims and were not independently confirmed.