Ransomware victim disclosure
← All victimsSampoerna Agro
Claimed by Medusa · listed 5 months ago
Status timeline
- Listed
Dec 19, 2025
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileSampoerna Agro is an Indonesian agribusiness company primarily engaged in the cultivation and processing of oil palm, as well as other agricultural commodities including sago and rubber. The company operates plantations and processing mills across Sumatra and Kalimantan, Indonesia. It is publicly listed on the Indonesia Stock Exchange (IDX: SGRO) and is part of the broader Sampoerna Group.
- Industry
- Palm Oil & Agricultural Commodities
- Employees
- 1001-5000
- Founded
- 1988
Attack summary
Severity: high — Data is listed as published by Medusa, a prolific ransomware-as-a-service group known for exfiltrating significant business data prior to publication. Sampoerna Agro is a publicly listed company, meaning leaked data could include financial records, operational data, employee PII, and commercially sensitive information. No specific data inventory is confirmable from the truncated post, but 'data_published' status elevates severity to high.The Medusa ransomware group claims an attack on Sampoerna Agro and has listed the disclosure status as data_published, indicating exfiltration and/or publication of company data. The specific contents of the published data cannot be confirmed from the truncated leak post due to a CAPTCHA verification wall.
What the group claims
Founded in 1993 and headquartered in South Sumatra, Indonesia, PT Sampoerna Agro Tbk is a palm oil manufacturer. They engage in the production of palm products, which are crude palm oil (CPO) and palm kernel (PK); palm kernel products, which include palm kernel oil and palm kernel expelle; germinated palm seeds, and non- palm oil products. The company headquarters is located Sampoerna Agro headquarters: Sampoerna Strategic Square, North Tower 28th Floor, Jl. Jenderal Sudirman Kav. 45, Jakarta 12930, Indonesia. 5K - 10K Employees
The leak post
captured from the group's siteHuman Verify Human verification required We need to ensure you're a real person. Please solve the captcha below to continue. Verify
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
