Ransomware victim disclosure
← All victimsHungry Lion
Claimed by Medusalocker · listed 11 hours ago
Status timeline
- ListedAug 27, 2026
- Data leakeddate unknown
At a glance
- Group
- Medusalocker
- Status
- Data leaked
- Country
- Ghana
- Sector
- Retail & E-Commerce
- Listed on leak site
- Aug 27, 2026
About the victim
AI dossier — public-source company profileHungry Lion is a fast food franchise operating across southern Africa, offering burgers, chicken, chips, and ice cream. The chain operates 111 locations across South Africa, Botswana, Namibia, Zambia, Zimbabwe, Lesotho, and Mauritius.
- Industry
- Quick Service Restaurant / Fast Food Franchising
Attack summary
Severity: high — Confirmed exfiltration of operational POS data across multiple systems from a multi-country franchise network. POS systems typically contain transaction records, potentially including payment card data, customer information, and business metrics. Scale across 111 locations and three distinct systems elevates impact.MedusaLocker claims to have exfiltrated data from Hungry Lion's point-of-sale systems. The group advertises access to three POS systems: Unity POS (242MB monthly data), GAAP POS (daily data), and CoSoft POS (145 terminals).
Data the group says was taken
AI dossier — extracted from the leak post- POS transaction records (Unity POS)
- Daily sales data (GAAP POS)
- Terminal transaction data (CoSoft POS, 145 terminals)
What the group claims
Fast food franchise (burgers, chicken, chips, ice cream) - 111 locations across South Africa, Botswana, Namibia, Zambia, Zimbabwe, Lesotho, Mauritius. Three POS systems: Unity POS (242MB monthly), GAAP POS (daily), CoSoft POS (145 terminals). | Botswana
Sources
Source
Indexed 11 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

