Globes Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Globes Listed by medusa Ransomware Group (reported July 18, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 18 July 2024 the Israeli business periodical Globes appeared on a listing published by the medusa ransomware group. The group claims it carried out a ransomware attack and exfiltrated internal files. The number of people whose information may be involved remains unknown, and public detail about exactly what was taken is limited. For anyone who works with, subscribes to, or has shared information with Globes, the practical stakes are straightforward: personal or professional data that once sat inside the organisation’s systems may now be in the hands of criminals who specialise in monetising stolen material.
Because the scale and precise contents of the claimed theft have not been independently confirmed, people connected to the publisher cannot yet know whether their own records are among the files. That uncertainty itself is the immediate problem—until more information surfaces, the safest course is to treat the possibility of exposure as real and take basic protective steps.
Inside the incident
Public reporting on the incident is sparse. On 18 July 2024 Globes was listed by the medusa ransomware group. The listing asserts that internal files were exfiltrated during a ransomware attack. No further technical details—such as the date the intrusion began, the method of initial access, the volume of data removed, or any ransom demand—have been disclosed in the available record. The number of people affected is listed as unknown. Beyond the group’s claim that internal files were taken, nothing more specific about the attack timeline or its operational impact has been confirmed by independent sources.
In short, the only established facts are the date of the listing, the identity of the claimed attacker, and the assertion that internal files left the organisation’s control. Everything else remains undisclosed.
Who is medusa?
Medusa is a well-documented ransomware group that operates a ransomware-as-a-service model. It typically gains access to corporate networks, encrypts systems, and simultaneously exfiltrates data so it can threaten public release if a ransom is not paid—a tactic known as double extortion. The group maintains a leak site where it posts victim names and, in many cases, samples of stolen material to increase pressure. Medusa has previously targeted organisations across multiple sectors and geographies; its public listings are claims that must be treated as unverified until corroborated by the victim or by independent forensic work. In this instance the group claims Globes is among its victims and that internal files were removed; those assertions have not been confirmed by Globes itself in the material available here.
Who is Globes?
Globes is an Israeli periodical that specialises in business journalism. Its coverage focuses on management, investment, technology, law, accounting and marketing. The corporate office is located at 53 Etzel Street, Rishon LeZiyyon, Central District, 75706, Israel, and the organisation employs 298 people. As a business-news publisher, Globes sits at the intersection of media and commercial information: it maintains relationships with sources, advertisers, subscribers and corporate subjects, and it stores the operational data required to produce and distribute its reporting. A breach at such an organisation is consequential because the data it holds can include both journalistic material and the personal or commercial details of people who interact with the publication.
What data was at risk
The only data type named in the available facts is “internal files exfiltrated in ransomware attack.” No further breakdown—employee records, subscriber lists, source communications, financial documents or otherwise—has been disclosed. Organisations of this kind typically hold employee personal data, contact details of sources and advertisers, subscription information, editorial drafts and internal correspondence. Whether any of those categories were among the files claimed by medusa remains unconfirmed. Readers should therefore treat the exact contents of the exfiltration as unknown rather than assume any particular category of data was or was not taken.
Why it matters
For individuals, the risk is practical rather than abstract. If personal identifiers, contact details or professional correspondence were among the internal files, those records can be used for targeted phishing, social-engineering attempts or identity fraud. Business contacts whose information appears in the material may face similar exposure. For Globes itself the consequences include potential disruption of editorial operations, loss of source confidence and the longer-term costs of investigation and remediation. Because the number of affected people is unknown and the precise data types remain undisclosed, the full scope of harm cannot yet be measured; the prudent assumption is that anyone who has shared information with the organisation should monitor for unusual activity.
The listing also illustrates a broader pattern: ransomware groups increasingly publicise victims to amplify pressure, regardless of whether negotiations are under way. That public claim alone can create secondary risks—copycat phishing campaigns that impersonate the organisation, for example—even before any data is released.
What to do if you're exposed
If you have reason to believe your information may have been held by Globes, begin with the basics. Change passwords on any accounts that used the same credentials you may have shared with the organisation, and enable multi-factor authentication wherever it is offered. Watch bank and credit-card statements for unexpected activity and consider placing a fraud alert or credit freeze with the major credit bureaux if you live in a jurisdiction that provides those tools. Be sceptical of unsolicited emails or calls that reference Globes or recent business news; treat them as potential phishing until verified through a trusted channel. Finally, you can run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets; that simple check can give an early indication of whether further monitoring is warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Inmobiliaria Armas Listed by medusa Ransomware GroupLevicoff Law Firm, P.C Listed by medusa Ransomware GroupDown East Granite Listed by medusa Ransomware GroupBrodsky Renehan Pearlstein & Bouquet, Chartered Listed by medusa Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Globes Listed by medusa Ransomware Group →
Publicly posted by medusa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.