Hairstore Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On September 11, 2024, the Medusa ransomware group listed Hairstore as a victim, stating that internal files had been exfiltrated. Individuals associated with the company are advised to check whether their data was involved and to follow any guidance issued by Hairstore.
Ransomware groups continue to target mid-sized suppliers across Europe, using double-extortion tactics that combine encryption with the threat of public data leaks. In this landscape, listings on criminal leak sites have become a common way for attackers to pressure victims and advertise their operations. On 11 September 2024, the Norwegian company Hairstore appeared on one such site operated by the Medusa ransomware group, which claimed responsibility for a ransomware attack that involved the exfiltration of internal files.
Public detail remains limited. The listing states that 52.30 GB of data was taken, but the number of people affected is unknown and the precise contents of the files have not been independently confirmed. For customers, employees and business partners of a specialist supplier, even an unverified claim of this kind raises practical questions about what may have been exposed and what steps are sensible next.
Inside the incident
According to the information available, Hairstore was listed by the Medusa ransomware group on 11 September 2024. The group claims that internal files were exfiltrated during a ransomware attack and that the total volume of data involved is 52.30 GB. No further technical details—such as the initial access vector, the encryption status of systems, or the timeline of the intrusion—have been disclosed in the public record surrounding this listing.
The number of individuals potentially affected is unknown. There is no public confirmation from Hairstore itself regarding the accuracy of Medusa’s claims, the scope of any compromise, or whether ransom negotiations took place. In the absence of additional statements or regulatory filings, the incident rests on the group’s leak-site assertion that internal files were taken and that the data volume reaches 52.30 GB.
Inside medusa
Medusa is a well-documented ransomware operation that has been active for several years. Like many contemporary groups, it typically follows a double-extortion model: after gaining access to a network, operators encrypt systems and simultaneously exfiltrate data, then threaten to publish the stolen material if a ransom is not paid. The group maintains a public leak site where it posts victim names, sample files and, in some cases, full data archives once deadlines expire.
Medusa has been observed targeting organisations across multiple sectors and geographies, often focusing on entities that hold operational or customer data of commercial value. Its operators have historically used common initial-access methods such as phishing, exploitation of unpatched remote-access services, and compromised credentials. Once inside, they move laterally, disable security tools where possible, and stage data for exfiltration before deploying the ransomware payload. The listing of Hairstore follows this established pattern of public naming and volume claims; the group’s assertion that 52.30 GB of internal files were taken should be treated as an unverified claim unless independently corroborated.
Hairstore and its sector
Hairstore is a supplier of consumables and equipment for hairdressers. Its corporate office is located at 134 Elveveien, Larvik, Vestfold, 3271, Norway. Companies of this type typically sit in the middle of a supply chain that serves salons, freelancers and retail outlets, handling product catalogues, order histories, invoicing records and logistics information.
A breach at a specialised wholesale supplier can have ripple effects beyond the organisation itself. Hairdressing businesses often rely on a limited number of trusted distributors for tools, colour products and consumables; disruption or data exposure at that level can affect pricing, stock availability and customer relationships. Because such firms routinely process commercial correspondence, payment details and contact information for both professional clients and end consumers, any compromise of internal systems raises questions about the confidentiality of those records.
What was likely exposed
The only data type named in connection with the incident is “internal files” said to have been exfiltrated in a ransomware attack. The total volume claimed is 52.30 GB. No further breakdown—such as whether the files included customer databases, employee records, financial documents, contracts or system backups—has been publicly disclosed.
Organisations operating as wholesale suppliers of salon equipment and consumables commonly hold order and invoice data, customer and supplier contact lists, inventory records, shipping details and internal administrative documents. They may also retain employee information and, in some cases, limited payment or credit details. Because the exact contents of the 52.30 GB claimed by Medusa remain unconfirmed, it is not possible to state with certainty which of these categories, if any, were included. Readers should treat any specific assertion about particular data types as unverified until official confirmation is available.
Why it matters
For individuals whose details may have been held by Hairstore—salon owners, freelancers, employees or end customers—the primary risks are secondary misuse of contact information, targeted phishing, or social-engineering attempts that reference genuine business relationships. Even limited internal files can contain enough context for attackers to craft convincing messages. Commercial partners face the additional possibility that pricing, contract or logistics data could be used by competitors or for further fraud.
For Hairstore itself, a public ransomware listing can damage trust with the professional hairdressing community it serves, create regulatory notification obligations under European data-protection rules, and impose costs related to investigation, system recovery and customer communication. Because the number of people affected is unknown and the precise data types remain undisclosed, the full scale of these consequences cannot yet be measured. The incident nevertheless illustrates how mid-sized suppliers, often less visible than large retailers, remain attractive targets for groups that specialise in double extortion.
Were you affected?
If you have done business with Hairstore—as a salon, freelancer, employee or supplier—consider monitoring accounts and communications for unusual activity. Change passwords on any related services, enable multi-factor authentication where available, and treat unsolicited messages that reference hair-industry suppliers or recent orders with caution. Watch financial statements for unexpected charges.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Such a check does not confirm or rule out involvement in this specific incident, but it provides a practical starting point for understanding your wider exposure and deciding whether further steps, such as credit monitoring or direct contact with Hairstore, are warranted.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Østerås Bygg Listed by medusa Ransomware GroupInmobiliaria Armas Listed by medusa Ransomware GroupLevicoff Law Firm, P.C Listed by medusa Ransomware GroupDown East Granite Listed by medusa Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Hairstore Listed by medusa Ransomware Group →
Publicly posted by medusa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.