Medusa ransomware gang demanded US$700,000 from Victoria Racing Club

Organization
Victoria Racing Club
Exploit
Ransomware
Industry
Sports and Recreation

The Victoria Racing Club, the Melbourne body that runs Flemington Racecourse and the Melbourne Cup Carnival, confirmed on 14 June 2024 that an unauthorised third party had accessed its systems. Chief executive Steve Rosich said the club had detected the intrusion, moved to contain it and engaged external security specialists, and that racing and club operations were continuing as normal.

The Medusa ransomware operation claimed the attack and dated it to 13 June. Cyber Daily, which reviewed the group's dark web listing, reported that Medusa claimed 128.1 gigabytes of club data and demanded US$700,000 either to delete the files or to sell them to a third party, with a further US$10,000 charged for each day the deadline was extended.

Sample files published by the gang included records on the club's gaming machines, financial detail on machine takings and member prizes, customer invoices, marketing material, and names, email addresses and mobile phone numbers. Much of the material appeared dated, although some ran to 2023.

The club reported the incident to the Australian Cyber Security Centre and wrote to employees, members, partners and sponsors. Medusa published the full 128.1 gigabytes by 26 June. The club said it was urgently reviewing the release, and that member information was generally held on a separate server it had found no evidence the attacker had interacted with, viewed, modified or copied.

Sources