Compass Group Australia confirmed Medusa ransomware attack
- Organization
- Compass Group Australia
- Exploit
- Ransomware
- Industry
- Food Services
Compass Group Australia, the local subsidiary of the UK listed catering and support services company Compass Group PLC, confirmed in September 2024 that it had been hit by the Medusa ransomware operation. The Australian business employs around 13,000 people and supplies food and facilities services to mine sites, defence bases, schools, hospitals and aged care facilities.
The company said its security monitoring detected unauthorised activity on a recently reactivated server on 4 September 2024. It activated its incident response plan, proactively disabled the affected systems, engaged external forensic specialists and legal counsel, and said no further malicious activity had been detected. The Australian Cyber Security Centre and the Office of the Australian Information Commissioner were both notified, and the company began contacting individuals whose higher risk data was involved.
Medusa listed Compass Group on its darknet leak site around 17 September 2024, claiming 785.5 GB of stolen data and setting an eight day deadline. The gang sought US$2 million to delete the material or to sell it outright, and offered to extend the deadline for US$100,000 a day. Sample documents it published included employee wage declarations and scans of international passports and driver's licences.
Medusa listed Compass Group a second time on the evening of 18 September 2024, a day after the first listing. The affiliate said it had entered the network again that morning and demanded US$100,000. Compass Group confirmed the second intrusion to Cyber Daily on 20 September.