LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Expert E-commerce GmbH Listed by medusa Ransomware Group

HIGH severityUnverified claimHow we verify

Expert E-commerce GmbH Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 18, 2025
Expert E-commerce GmbH Listed by medusa Ransomware Group

Reported July 18, 2025.

HIGH
Severity
July 18, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Expert E-commerce GmbH was listed by the Medusa ransomware group on July 18, 2025, after internal files were exfiltrated in an attack whose date has not been established. Individuals who have done business with the company should check whether their information was affected and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Expert E-commerce GmbH, a German firm that supports specialist retail stores with online services, has been listed by the medusa ransomware group as a victim of a data-exfiltration attack. Public reporting dated 18 July 2025 states that 114 GB of internal files were taken. The number of people affected remains unknown, and further technical details of the intrusion have not been disclosed.

The listing itself is a claim published on the group’s leak site. It matters because the company sits inside a wider retail network and handles operational data that can affect both partner stores and the customers those stores serve. Until more is confirmed, the scale of personal impact cannot be measured with certainty.

Breaking down the breach

According to the available record, Expert E-commerce GmbH was named by medusa on or around 18 July 2025. The group asserts that it exfiltrated 114 GB of internal files during a ransomware attack. No public statement from the company confirming or denying the claim has been included in the source material, and no independent verification of the volume or contents has been released.

The method of initial access, the duration of the intrusion, and whether encryption was also deployed remain undisclosed. The only concrete figure supplied is the claimed 114 GB of data. The number of individuals whose information may be contained in those files is listed as unknown. No ransom demand amount, negotiation timeline, or proof-of-leak samples beyond the group’s own listing have been detailed in the facts provided.

Inside medusa

Medusa is a ransomware operation that has been active for several years and is known for a double-extortion model: data is stolen before systems are encrypted, and the threat of public release is used to pressure payment. The group maintains a dedicated leak site where it posts victim names, sample files, and countdown timers. Public reporting on earlier campaigns shows that medusa typically targets mid-sized organisations across Europe and North America, often focusing on sectors that hold operational or customer-related records.

Tactics commonly associated with the group include phishing or exploitation of unpatched remote-access services, followed by lateral movement and large-scale data collection. Once inside a network, operators have historically used commodity tools for credential theft and data staging before deploying their ransomware payload. The listing of Expert E-commerce GmbH follows this established pattern of public naming; any specific claims made by the group about this particular company beyond the 114 GB figure and the “internal files” description should be treated as unverified assertions until corroborated.

Expert E-commerce GmbH and its sector

Expert E-commerce GmbH was established in 1999 and is headquartered in Langenhagen, Germany. It specialises in e-commerce services that provide online support to the participating specialist stores of the Expert SE group. In practical terms, the company acts as a central technology and logistics partner for a network of independent electronics and appliance retailers, helping them operate web shops, manage inventory visibility, and process customer orders.

Organisations of this type typically sit between physical retail and digital sales channels. They therefore hold supplier catalogues, store-level sales data, customer order histories, payment-related records, and internal administrative files. Because the firm supports multiple partner stores, a compromise can extend beyond a single corporate boundary and affect the wider Expert retail ecosystem. The consequential nature of a breach here stems from that connective role: operational disruption or data exposure can ripple outward to stores and their customers even if those parties were never direct targets.

What was likely exposed

The facts state that internal files were exfiltrated and that the total volume claimed is 114 GB. No further breakdown of file types, databases, or personal-data categories has been published. Exact contents therefore remain unconfirmed.

Companies that deliver e-commerce infrastructure for retail networks commonly store order records, customer contact details, delivery addresses, product catalogues, pricing agreements, employee directories, and internal correspondence. Whether any of those categories were present in the 114 GB archive cannot be verified from the available information. Readers should treat any more specific inventory of exposed data as speculative until the company or independent investigators release a confirmed list.

What's at stake

For individuals whose data may have been included, the primary risks are phishing, identity fraud, and unwanted marketing contact. Order histories and contact details can be used to craft convincing social-engineering messages. Financial or payment-related fragments, if present, raise the possibility of account-takeover attempts. Because the number of affected people is unknown, the breadth of this exposure cannot yet be quantified.

For Expert E-commerce GmbH and its partner stores, the stakes include operational disruption, contractual liability toward the Expert SE network, regulatory scrutiny under European data-protection rules, and reputational damage that may affect customer trust in the online channels the company supports. Even if systems have been restored, the continued existence of the stolen archive outside the organisation’s control creates an ongoing risk of secondary leaks or sale on criminal markets.

What to do if you're exposed

Anyone who has shopped at Expert-affiliated stores or worked with the company should treat the possibility of exposure seriously until more details emerge. Begin by changing passwords on any accounts that reuse credentials linked to those stores, and enable multi-factor authentication where available. Monitor bank and credit statements for unexpected activity, and be sceptical of unsolicited emails or calls that reference recent purchases or account details. Consider placing a fraud alert with credit-reference agencies if you live in a jurisdiction that offers that service.

As a practical next step, readers can run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a scan will not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant the same protective measures.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyExpert E-commerce GmbH security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Expert E-commerce GmbH’s full breach history →

More recent breaches

Shamrock Technologies Listed by medusa Ransomware GroupDecember 13, 2025Imagicle Listed by medusa Ransomware GroupOctober 19, 2025DSI Tech Listed by medusa Ransomware GroupMay 14, 2025Krypton Solutions Listed by medusa Ransomware GroupApril 1, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Expert E-commerce GmbH Listed by medusa Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by medusa — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram