LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Addison Saws Listed by medusa Ransomware Group

HIGH severityUnverified claimHow we verify

Addison Saws Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·January 29, 2025
Addison Saws Listed by medusa Ransomware Group

Reported January 29, 2025.

HIGH
Severity
January 29, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Addison Saws was listed by the Medusa ransomware group on January 29, 2025, after internal files were exfiltrated in a ransomware attack. The number of individuals affected has not been disclosed; anyone who has done business with the company should check for unusual account activity and consider changing passwords.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal or work-related details may sit inside company systems at Addison Saws face a practical question: whether internal files taken in a claimed ransomware incident could expose them to fraud, unwanted contact, or further targeting. Public reporting so far leaves the number of individuals involved unknown and the precise contents of those files unconfirmed, yet the listing itself is enough to warrant careful attention from anyone who has dealt with the firm.

On 29 January 2025 Addison Saws was named on the leak site of the ransomware group known as medusa. The group claims that internal files were exfiltrated during a ransomware attack. No independent confirmation of the scale or full contents has been made public, and the company has not been shown in available records to have issued a detailed public statement on the matter.

Breaking down the breach

What is known rests on the medusa group’s listing of Addison Saws. According to that claim, internal files were taken as part of a ransomware operation. The date the listing appeared in public reporting is 29 January 2025. No figure for the number of people affected has been disclosed. No technical description of how the attackers gained access, how long they remained inside the network, or whether systems were encrypted has been released in the available record. The only data category named is “internal files.” Everything beyond that claim remains undisclosed.

Ransomware incidents of this type typically involve both encryption of systems and the theft of data for leverage. In this case the public facts stop at the group’s assertion that files were exfiltrated. Without further official disclosure it is not possible to state whether backups were affected, whether operations were interrupted, or how much data left the organisation.

The group behind it: medusa

Medusa is a well-documented ransomware operation that has been active for several years. Like many contemporary groups it follows a double-extortion model: systems are encrypted and copies of data are removed so that the threat of public release can be used to pressure payment. The group maintains a leak site on which it lists organisations it claims to have compromised and, if its demands are not met, publishes samples or larger volumes of stolen material.

Public reporting on medusa has shown a pattern of targeting mid-sized and larger organisations across manufacturing, professional services and other sectors. The group typically advertises stolen data packages and sets deadlines. Its listings are claims made by the attackers themselves; they are not independent verification that every file described was in fact taken or that every organisation named was successfully breached. In the present case the only established fact is that Addison Saws appears on the group’s site with the assertion that internal files were exfiltrated.

Addison Saws and its sector

Addison Saws is a United Kingdom company founded in 1956. Its corporate office is recorded at Attwood Street, Lye, Stourbridge. The firm specialises in industrial metal-cutting solutions, supplying bandsaws, cold saws, tube benders, laser cutters and saw blades to the metal-working industry. Organisations of this kind sit inside manufacturing supply chains; they hold commercial contracts, supplier and customer records, employee information and technical documentation related to equipment and processes.

A breach affecting such a company is consequential because manufacturing firms routinely store data that can be used for business-email compromise, invoice fraud or competitive intelligence. Even when the primary target is the organisation itself, the secondary risk falls on individuals whose contact details, employment records or project information may have been among the internal files. The sector’s reliance on long-term supplier relationships also means that a single incident can create ripple effects for partners who share data with the affected firm.

The information in question

The only category named in the public facts is “internal files exfiltrated in a ransomware attack.” No inventory of those files has been released. It is therefore not possible to state as fact that any particular type of personal data—names, addresses, financial details, health information or otherwise—was included.

Companies operating in industrial equipment supply typically maintain employee records, customer and supplier contact lists, purchase orders, technical drawings, pricing information and internal correspondence. Any of those materials could fall under the broad heading of “internal files.” Until a fuller disclosure is made, the exact contents remain unconfirmed. Readers should treat claims about specific data types as unverified unless they come from the organisation itself or from a competent authority.

The real-world impact

For individuals the concrete risks are familiar: phishing that uses accurate internal context, attempts to reset accounts with known personal details, or fraudulent invoices that appear to come from a trusted supplier. Because the number of people affected is unknown, it is impossible to say how widely those risks may spread. Employees, former staff, customers and suppliers who have exchanged documents with Addison Saws are the groups most likely to need to remain alert.

For the organisation the impact centres on operational disruption, potential regulatory notification duties under UK data-protection law, and the commercial cost of restoring systems and rebuilding trust with partners. The absence of public figures for data volume or ransom demand means these consequences cannot yet be quantified from open sources. The listing itself, however, already places the company under external pressure and may prompt customers to reassess how they share information.

What to do if you're exposed

Anyone who has worked with or for Addison Saws should treat the incident as a prompt for basic hygiene rather than panic. Change passwords on any accounts that may have been used in correspondence with the firm, enable multi-factor authentication where it is available, and watch for unexpected emails or calls that reference internal projects or invoices. Monitor bank and credit statements for unusual activity. If you receive a notification directly from the company, follow the instructions it provides.

Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a check does not prove involvement in this specific incident, but it can surface other exposures that warrant the same protective steps. Keep records of any suspicious contact and report confirmed fraud to the relevant authorities.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyAddison Saws security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Addison Saws’s full breach history →

More recent breaches

LGB Listed by medusa Ransomware GroupOctober 3, 2025Advance Tapes International Listed by medusa Ransomware GroupMarch 21, 2025CPI Books Listed by medusa Ransomware GroupMarch 6, 2025English Braids Listed by medusa Ransomware GroupJanuary 29, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Addison Saws Listed by medusa Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by medusa — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram