Ransomware victim disclosure
← All victimsATIRG
Claimed by Medusa · listed 7 months ago
Status timeline
- Listed
Oct 27, 2025
- Data leaked
At a glance
- Group
- Medusa
- Status
- Data leaked
- Country
- French Guiana
- Sector
- Not Found
- Listed on leak site
- Oct 27, 2025
About the victim
AI dossier — public-source company profileATIRG is a company based in French Guiana. No public site content or leak post details were available to determine the nature of its operations, scale, or industry.
Attack summary
Severity: medium — Data is marked as published by the group, indicating confirmed exfiltration rather than a mere listing, but no details about data type, scale, or sensitivity are available to elevate to high or critical.Medusa ransomware group has listed ATIRG with a disclosed status of 'data_published', suggesting data exfiltration has occurred; however, no specific claims about encryption, data types, or volume were extractable from the truncated leak post.
What the group claims
ATIRG (Association pour le Traitement de l’Insuffisance Rénale en Guyane) is a non-profit medical organization located in French Guiana, dedicated to providing dialysis treatment and kidney care for patients suffering from chronic renal failure. Established in 1981, ATIRG operates several autodialysis centers in Cayenne, Kourou, and Saint-Laurent-du-Maroni, offering patients the opportunity to manage their own dialysis under professional supervision. The organization focuses on improving patients’ quality of life through medical care, training, and nutritional support. ATIRG works closely with local hospitals and healthcare professionals to ensure safe, effective, and continuous kidney treatment across the region. company is headquartered in 1361 Route de Baduel, 97300 Cayenne, French Guiana.
The leak post
captured from the group's siteHuman Verify Human verification required We need to ensure you're a real person. Please solve the captcha below to continue. Verify
Sources
Source
Indexed 7 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
