Grace Church International Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Grace Church International Listed by medusa Ransomware Group (reported January 11, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
When a church community appears on a ransomware group's leak site, the practical concern is straightforward: internal files may have left the organisation's control, and people connected to that community cannot yet know whether their own information is among what was taken. Public reporting on 11 January 2023 stated that Grace Church International had been listed by the group known as medusa, with the claim that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further specifics have not been disclosed.
For congregants, staff, volunteers and anyone who has shared personal details with a church, that uncertainty itself carries weight. Religious organisations routinely hold contact information, pastoral notes and administrative records; until more is confirmed, those whose data may be involved are left to weigh ordinary precautions against incomplete public detail.
What happened
According to public reporting dated 11 January 2023, Grace Church International was listed by the medusa ransomware group. The available account states that internal files were exfiltrated in a ransomware attack. No confirmed figure for the number of people affected has been published, and details such as the precise timing of the intrusion, the method of initial access, the volume of data taken, or whether encryption was also deployed on the organisation's systems remain undisclosed in the material at hand.
The listing itself is a claim advanced by the group on its leak site. Independent confirmation of the full scope of the incident has not been provided in the reported facts, so the public record rests on that claim together with the characterisation of the event as a ransomware attack involving exfiltration of internal files.
The group behind it: medusa
Medusa is a known ransomware operation that has appeared in public reporting over recent years as a group that conducts double-extortion attacks. In the pattern associated with such actors, operators typically gain access to a victim network, move laterally to locate valuable data, exfiltrate copies, and then deploy ransomware to encrypt systems while threatening to publish the stolen material if a payment is not made. The group has used dedicated leak sites to name organisations and, in some cases, to release samples or larger sets of data when negotiations fail or deadlines pass.
These tactics are well documented across multiple incidents attributed to medusa in open sources. With respect to Grace Church International specifically, the facts state only that the organisation was listed and that internal files were described as exfiltrated; no further claims by the group about this victim—such as ransom demands, deadlines, or sample file releases—are included in the reported material. Any assertion beyond that listing should therefore be treated as unverified.
Grace Church International and its sector
Grace Church International is a religious organisation. The summary associated with the reporting reflects a faith community that emphasises biblical authority, prayer, faith and the family as foundational to church life, and the belief that each person has a uniquely designed purpose. Churches and similar ministries typically serve congregants through worship, pastoral care, community programmes and administrative functions that necessarily involve collecting and storing personal and organisational information.
A breach affecting a church is consequential because the sector often holds data that is both practical and sensitive: membership and contact lists, donation or giving records, volunteer and staff details, counselling or pastoral notes, and internal correspondence. Trust is central to how such communities operate. When internal files are reported as taken, the potential exposure reaches beyond financial or operational disruption to questions of privacy and confidence among people who shared information in a setting they regarded as confidential.
The information in question
The facts name the exposed material only as “internal files exfiltrated in a ransomware attack.” No inventory of specific data types—such as names, addresses, financial records, identity documents or pastoral notes—has been disclosed in the public account. The number of individuals whose information may be involved is likewise unknown.
Organisations of this kind commonly maintain membership directories, communication lists, employment or volunteer records, financial and donation data, and various internal documents. It is reasonable to recognise that such categories could be present among internal files, yet it is not established that any particular category was in fact taken. Exact contents remain unconfirmed, and no assumption should be treated as fact.
Why it matters
For individuals, the real-world risk centres on the possibility that personal details could be misused for phishing, social engineering or identity-related fraud. Even limited contact information can be combined with other publicly available data to craft convincing messages that appear to come from the church or from familiar community figures. If more sensitive records were among the files, the potential harm increases accordingly, though that remains unconfirmed here.
For the organisation, a ransomware incident that includes exfiltration can disrupt operations, strain resources needed for recovery and notification, and erode the trust on which a faith community depends. Because the scale and precise contents are undisclosed, both the church and those connected to it are operating with incomplete information—an uncomfortable but common situation in the early public phase of such events. Calm, practical steps matter more than speculation.
Were you affected?
If you have been connected with Grace Church International as a congregant, staff member, volunteer or donor, consider basic precautions. Monitor accounts and financial statements for unusual activity. Treat unexpected messages that reference the church or that urge urgent action with caution, and verify any request through a known, separate channel. Change passwords on important accounts if you reuse credentials, and enable multi-factor authentication where it is available. Keep records of any suspicious contact.
Public detail on this incident remains limited; the number of people affected is unknown and the exact data types beyond “internal files” are unconfirmed. Readers who wish to check whether their email address has appeared in known breach data sets can run a free exposure scan as one additional, practical step. Remaining attentive without alarm is the most useful posture while further information, if any, emerges.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Water For People Listed by medusa Ransomware GroupLeaguers Listed by medusa Ransomware GroupNative Counselling Services of Alberta Listed by medusa Ransomware GroupBeaver Lake Cree Nation Listed by medusa Ransomware GroupLatest breaches
Publicly posted by medusa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.