Ransomware victim disclosure
← All victimsJuntadeandalucia
Claimed by Medusalocker · listed 9 hours ago
Status timeline
- ListedSep 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Medusalocker
- Status
- Data leaked
- Country
- Spain
- Sector
- Government & Defense
- Listed on leak site
- Sep 28, 2026
About the victim
AI dossier — public-source company profileThe Junta de Andalucía is the regional autonomous government of Andalusia, Spain's most populous autonomous community. It administers public services across education, healthcare, employment, social services, infrastructure, and other devolved competencies for a population of approximately 8.5 million.
- Industry
- Government & Public Administration
- Address
- Seville, Andalusia, Spain (regional government seat)
- Employees
- 10000+
- Founded
- 1982
Attack summary
Severity: high — Confirmed exfiltration of government employee email accounts at a large autonomous regional administration. Email systems typically contain sensitive administrative, policy, and citizen data. Scale (198 accounts) and government target elevate risk despite lack of specified proof publication.MedusaLocker claims to have extracted 198 email accounts from the domain juntadeandalucia.es. The post does not specify whether encryption occurred or what categories of data were exfiltrated beyond email access.
Data the group says was taken
AI dossier — extracted from the leak post- email accounts (198)
What the group claims
Organization with 198 emails extracted. Domain: juntadeandalucia.es
Sources
Source
Indexed 9 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

