LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Grail Springs Retreat Listed by medusa Ransomware Group

HIGH severityUnverified claimHow we verify

Grail Springs Retreat Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·February 3, 2025
Grail Springs Retreat Listed by medusa Ransomware Group

Reported February 3, 2025.

HIGH
Severity
February 3, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Grail Springs Retreat was listed by the medusa Ransomware Group on February 03, 2025 after internal files were exfiltrated in a ransomware attack. An undisclosed number of individuals may have been affected; anyone connected to the retreat should check their records and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target organisations of every size, including smaller wellness and hospitality providers whose guest and operational records can hold sensitive personal information. In this landscape, listings on criminal leak sites serve as public pressure tactics even when independent confirmation of an intrusion remains limited. The appearance of Grail Springs Retreat on such a site therefore warrants careful attention from anyone who has stayed at or worked with the centre.

Public reporting dated 3 February 2025 states that the Medusa ransomware group has listed Grail Springs Retreat, claiming that internal files were exfiltrated in a ransomware attack. The number of people affected is unknown, and further technical detail about timing, method or scale has not been disclosed. The listing itself is a claim by the group; it has not been independently verified in the available record.

Breaking down the breach

According to the reported summary, Grail Springs Retreat was listed by the Medusa ransomware group on or around 3 February 2025. The group asserts that internal files were taken during a ransomware attack. No confirmed figures for the volume of data, the precise date of intrusion, or the number of individuals whose information may be involved have been released. Public detail on how the attackers gained access, whether encryption was deployed alongside theft, or whether any ransom demand was made remains undisclosed. In the absence of those specifics, the only established elements are the organisation’s appearance on the group’s leak site and the claim of internal-file exfiltration.

The group behind it: medusa

Medusa is a well-documented ransomware operation that has operated for several years under a double-extortion model. The group typically encrypts systems and simultaneously steals data, then threatens to publish the material on a dedicated leak site if payment is not received. Medusa has previously listed organisations across healthcare, education, manufacturing and professional services, often releasing sample files to demonstrate possession. Its operators maintain a public-facing portal where victims are named and, in some cases, data is staged for download. Because the listing of Grail Springs Retreat originates from that portal, it should be treated as an unverified claim by the group rather than confirmed evidence of a successful breach. No additional statements attributed specifically to Medusa about this victim beyond the listing itself appear in the available facts.

Who is Grail Springs Retreat?

Grail Springs Retreat is a spa and wellness centre located at 2004 Bay Lake Road, Bancroft, Ontario, Canada. It offers a range of programmes that include immunological therapy, energy work, body-focused treatments, vibro-acoustics and spiritual leadership services. The corporate office employs approximately twenty people. Organisations of this type routinely maintain guest reservation systems, health and intake questionnaires, payment records, employee files and internal operational documents. A compromise at such a facility can therefore touch both personal wellness data and the administrative backbone of a small hospitality business. Because the centre serves individuals seeking restorative and sometimes health-related programmes, any exposure of its records carries particular sensitivity for guests who may have shared medical or personal circumstances.

What data was at risk

The available facts state only that internal files were exfiltrated in a ransomware attack. No inventory of specific data categories—such as guest names, contact details, medical histories, payment card information or employee records—has been published. Wellness and spa centres typically hold reservation data, intake forms that may contain health information, billing records and staff personnel files. Whether any of those categories were among the files claimed by Medusa is unconfirmed. Until a fuller disclosure or independent verification appears, the exact contents of the material remain unknown.

The real-world impact

For individuals who have stayed at or worked with Grail Springs Retreat, the primary concern is the possible misuse of personal information if the group’s claim proves accurate and the files are later released or sold. Risks can include targeted phishing, identity fraud or unwanted contact that references private wellness details. For the organisation itself, the listing creates operational and reputational pressure: systems may need forensic review, guests may require notification, and regulatory obligations under Canadian privacy law could apply once the scope is clarified. Because the number of people affected is unknown and the data types remain unspecified, the concrete scale of harm cannot yet be measured. The incident nonetheless illustrates how even modestly sized retreats can become targets when attackers seek leverage through sensitive personal records.

Were you affected?

If you have been a guest, employee or vendor of Grail Springs Retreat, treat the listing as a prompt for caution rather than confirmed exposure. Monitor financial accounts and email for unusual activity, enable multi-factor authentication where available, and be sceptical of unsolicited messages that reference the centre or your stay. Consider placing a fraud alert with credit bureaus if you shared sensitive personal or payment information. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Official updates from the organisation or Canadian privacy authorities, once issued, will provide the most reliable guidance on next steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyGrail Springs Retreat security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Grail Springs Retreat’s full breach history →

More recent breaches

Thunder Bay Counselling Listed by medusa Ransomware GroupDecember 13, 2025Oscars Group Listed by medusa Ransomware GroupNovember 5, 2025LaRosa’s Pizzeria Listed by medusa Ransomware GroupNovember 5, 2025Leprohon Listed by medusa Ransomware GroupOctober 3, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Grail Springs Retreat Listed by medusa Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by medusa — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram