Medusa ransomware group claimed a NASCAR breach and demanded $4 million

Organization
NASCAR
Exploit
Ransomware
Industry
Sports & Entertainment

The Medusa ransomware group listed the National Association for Stock Car Auto Racing on its dark web leak site in early April 2025, claiming it had stolen internal files from the motorsport body and demanding $4 million to delete them.

Medusa published a set of screenshots as proof. Reporters who examined them described corporate branding material, raceway facility maps, spreadsheets of employee and sponsor contact details, invoices, financial reports and a directory listing of NASCAR's internal file structure. The group put the volume of stolen data at roughly one terabyte. Its leak site carried a countdown timer, with an option to delay publication for $100,000 per day.

NASCAR neither confirmed nor denied the claim at the time, so the figures came entirely from the attackers rather than from the organisation. Researchers who reviewed the samples said the material appeared credible.

NASCAR subsequently acknowledged the incident. It said an intruder was present on its network between 31 March and 3 April 2025, that it detected the activity on 3 April and that it confirmed on 24 June that personal information was involved. Notification letters went out from 24 July 2025 citing names and Social Security numbers, with a year of credit and identity monitoring through Experian and a call centre for enquiries. NASCAR did not publish a victim total, and the Medusa listing was later removed from the leak site.

Sources