American Golf Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The American Golf Listed by medusa Ransomware Group (reported July 12, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to pressure organisations across leisure, hospitality and retail by combining encryption with public data-leak threats. In that landscape, the listing of American Golf by the medusa ransomware group on 12 July 2024 is a concrete illustration of how operators of golf courses and country clubs have become targets. Public reporting states that the group claims to have exfiltrated 154.9 GB of internal files; the number of people affected remains unknown and the precise contents of those files have not been independently confirmed.
Because American Golf manages courses and clubs that hold membership, employee and operational records, any confirmed exposure of internal material can create lasting practical risks for individuals and for the business itself. The following account stays strictly within the disclosed facts and established public knowledge of the actor involved.
What happened
On 12 July 2024 American Golf appeared on the leak site operated by the medusa ransomware group. The listing asserts that the group conducted a ransomware attack in which internal files were exfiltrated, with a claimed total volume of 154.9 GB. No further technical details—such as the initial access vector, the date of intrusion, or whether systems were encrypted—have been made public. The number of individuals whose data may be involved is listed as unknown. The organisation’s corporate office is recorded as 909 N Pacific Coast Hwy, El Segundo, California, and it is described as employing 379 people. Beyond the leak-site claim and the stated data volume, no independent verification of the breach or of the exact files taken has been published.
Inside medusa
Medusa is a ransomware operation that has been active for several years and is known for double-extortion tactics: encrypting systems while simultaneously stealing data and threatening to publish it on a dedicated leak site if a ransom is not paid. The group typically posts victim names, claimed data volumes and sample files to increase pressure. Public reporting has linked medusa to attacks across multiple sectors, including manufacturing, professional services and leisure. Its operators have historically used phishing, compromised credentials and exploitation of remote-access services as entry points, though the specific method used against any individual victim is rarely confirmed unless the organisation itself discloses it. In the present case the only public assertion is the group’s own listing; that claim has not been independently corroborated in the available record.
About American Golf
American Golf is a long-established operator in the golf industry, functioning as owner, lessee and manager of golf courses and country clubs for more than fifty years. Its corporate headquarters is located in El Segundo, California, and the organisation reports approximately 379 employees. Companies of this type routinely manage membership databases, employee records, financial and operational documents, and communications with vendors and guests. Because golf clubs often serve as social and recreational hubs, they hold personal information that can include contact details, payment information, membership histories and, in some cases, health or accessibility notes. A ransomware incident that claims to have removed internal files therefore raises questions about the security of both business continuity and the personal data of members, staff and partners.
The information in question
The only data category named in public reporting is “internal files” said to have been exfiltrated in a ransomware attack, with a claimed volume of 154.9 GB. No inventory of file types, no sample documents and no confirmation of whether customer, employee or financial records were included have been released. Organisations that operate golf courses and country clubs typically hold membership rolls, payroll and human-resources files, contracts, invoices, facility plans and internal correspondence. Whether any of those categories formed part of the claimed 154.9 GB remains unconfirmed. Readers should therefore treat the precise contents as undisclosed until verified by the organisation or by independent forensic reporting.
The real-world impact
If the claimed files contain personal or financial information, affected individuals face the ordinary risks associated with data exposure: targeted phishing, identity-fraud attempts, and unsolicited contact that leverages knowledge of membership or employment status. For the organisation, the consequences can include operational disruption, regulatory notification obligations under state and federal privacy laws, potential contractual claims from partners, and reputational damage among members who expect discretion. Because the number of people affected is unknown and the exact data types are unconfirmed, the scale of these risks cannot yet be quantified. Even internal operational documents, if published, can reveal business relationships or security practices that adversaries might later exploit.
If your data was in this claimed breach
Anyone who has been a member, employee or vendor of American Golf should monitor financial accounts and credit reports for unusual activity and treat unsolicited emails or calls that reference golf-club membership with caution. Enable multi-factor authentication on email and financial accounts, and consider placing a fraud alert with the major credit bureaux if personal identifiers may have been involved. Because the precise contents of the claimed 154.9 GB remain unconfirmed, it is prudent to assume that contact and membership details could be at risk until official clarification is issued. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets; such a scan provides an additional early-warning signal while waiting for further public details about this incident.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Camp Susque Listed by medusa Ransomware GroupInside Broadway Listed by medusa Ransomware GroupLaRosa’s Pizzeria Listed by medusa Ransomware GroupSan Jose Country Club Listed by medusa Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the American Golf Listed by medusa Ransomware Group →
Publicly posted by medusa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.