Ransomware victim disclosure
← All victimsPraveg Caves Jawai
Claimed by Medusalocker · listed 23 hours ago
Status timeline
- ListedSep 12, 2026
- Data leakeddate unknown
At a glance
- Group
- Medusalocker
- Status
- Data leaked
- Country
- India
- Sector
- Hospitality
- Listed on leak site
- Sep 12, 2026
About the victim
AI dossier — public-source company profilePraveg Caves Jawai is a luxury safari resort located near the Jawai leopard reserve in Sumerpur, Rajasthan, India. The property operates restaurant and bar facilities (Panthera and Panthera Bar) and offers safari tours, with distribution through online travel agencies including MakeMyTrip, Goibibo, and Swiftbook.
- Industry
- Luxury Safari Resort & Hospitality
- Address
- Near Jivda Gate, Bija Pur Road, Bijapur, Jawaband Road, Sumerpur (Pali), Rajasthan, 306126, India
Attack summary
Severity: high — Confirmed data exfiltration from a hospitality business with customer PII from multiple OTA channels; hotel PMS/POS systems typically contain guest personal data, payment information, and booking history at scale.MedusaLocker claims to have compromised the resort's IDS Fortune V5 hotel management and point-of-sale system. The group has published data allegedly exfiltrated from the victim, including customer information accessible through their booking channels.
Data the group says was taken
AI dossier — extracted from the leak post- Hotel management system records (IDS Fortune V5)
- Point-of-sale transaction data
- Customer booking information
- Staff employee records
What the group claims
Luxury safari resort near Jawai leopard reserve, Sumerpur (Pali), Rajasthan, India (phone +91 777 908 4007). Runs IDS Fortune V5 hotel PMS/POS (customer code 9473, runtime C:\Program Files\IDS\FortuneV5runtime); restaurant PANTHERA and Panthera Bar; safari tours; OTAs: MakeMyTrip, Goibibo, swiftbook.io, Journey Expeditions; staff: HARSH, VINODK, ATANU, ADITYA THAKUR. | Near Jivda Gate, Bija Pur Road, Bijapur, Jawaband Road, Sumerpur (Pali), Rajasthan, 306126
Sources
Source
Indexed 23 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

