Ransomware victim disclosure
← All victimsActionAid International
listed as ActionAid / TACOSA · Claimed by Medusalocker · listed 1 month ago
Status timeline
- ListedMay 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Medusalocker
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Public Sector
- Listed on leak site
- May 5, 2026
About the victim
AI dossier — public-source company profileActionAid International is a global federation NGO working to combat poverty and injustice. The organization operates teams across multiple continents with a focus on women's rights, land and climate issues, politics and economics, and emergency response. They maintain operations in Africa, Asia, Oceania, Europe, and the Americas.
- Industry
- International Non-Governmental Organization (NGO) / Humanitarian Aid
Attack summary
Severity: high — ActionAid is a major international NGO with significant humanitarian operations and donor networks. Compromise of such an organization poses risks to vulnerable populations they serve, their staff, and their donor base. The involvement of government domains (Tanzania immigration) elevates concern, though the exact data scope is unclear.MedusaLocker claims to have compromised ActionAid International and associated entities including TACOSA and Tanzania immigration infrastructure. The group has published data but specific details on exfiltration scope or encryption status are not elaborated in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- organizational records
- donor information
- operational documents
- staff data
What the group claims
NGO sector. Domains: actionaid.org, tacosa.org.za, immigration.go.tz.
Sources
Source
Indexed 1 month agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

