International Center of Photography Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The International Center of Photography Listed by medusa Ransomware Group (reported February 19, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On February 19, 2023, the International Center of Photography was listed by the medusa ransomware group, which claimed to have exfiltrated internal files in a ransomware attack. The number of people affected remains unknown, and public detail on the incident is limited to that listing and the description of internal files taken.
For an institution dedicated to photography and visual culture, any confirmed exposure of internal material raises practical questions about staff, donors, partners, and operational records. What is established so far is the group’s claim and the reported nature of the data; independent confirmation of scope and contents has not been detailed in the available record.
What happened
According to the reported information, the International Center of Photography appeared on a medusa ransomware leak site on or around February 19, 2023. The group’s listing described internal files as having been exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the precise date of initial access, or the technical method used. The number of people affected is unknown. Beyond the claim that internal files were taken, further operational details of the incident have not been disclosed in the facts available.
Ransomware incidents of this type typically involve unauthorized access followed by data theft and, in many cases, encryption of systems. Whether encryption occurred here, whether a ransom demand was issued, and whether any negotiation took place are not stated in the public summary. The core documented fact is the group’s assertion that it held and intended to leverage internal files belonging to the organization.
Who is medusa?
Medusa is a known ransomware operation that has appeared in public reporting as a group using double-extortion tactics: stealing data before or alongside encrypting systems, then threatening to publish the material if payment is not made. Like other groups in this category, it has maintained a leak site on which it names victims and, in some cases, releases samples or full archives when its demands are unmet. Public tracking of ransomware activity has associated medusa with attacks across multiple sectors rather than a single industry focus.
Listings on such sites are claims by the threat actor. They indicate that the group asserts it has compromised the named organization and possesses data; they do not by themselves constitute independent verification of every detail. In this case, the facts record that International Center of Photography was listed and that internal files were described as exfiltrated. No additional statements attributed to medusa about this specific victim—such as file counts, ransom amounts, or deadlines—are included in the available record, and none should be assumed.
Who is International Center of Photography?
The International Center of Photography is a New York–based institution focused on photography and visual culture. It was founded in 1974 by Cornell Capa to champion “concerned photography”—socially and politically minded images intended to educate and influence public understanding. The organization has been described as employing on the order of 374 people and operates as a leading center for exhibitions, education, collections, and public programs related to the photographic medium.
Institutions of this kind typically hold a mix of administrative, educational, and cultural records. That can include staff and contractor information, donor and membership data, student or program-participant details where education is offered, vendor and partner contracts, and digital or digitized collection-related materials and internal correspondence. A breach affecting such an organization matters because the data often touches employees, supporters, collaborators, and sometimes the public who engage with its programs—not only internal business files.
What was likely exposed
The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types—such as names, contact details, financial records, identity documents, or collection inventories—has been disclosed. The exact contents therefore remain unconfirmed.
Organizations in the museum, cultural, and educational sector commonly maintain human-resources files, payroll and benefits records, fundraising and donor databases, membership lists, email and document repositories, and operational systems that support exhibitions and schools. Any of those categories could fall under a broad label of “internal files,” but it would be inaccurate to treat them as verified exposures in this incident. Until a fuller inventory is published by the organization or corroborated through independent reporting, the prudent position is that internal material was claimed stolen and that the precise sensitivity and breadth of that material are not publicly established.
The real-world impact
For individuals whose information may have been among the taken files, risks are the familiar ones associated with organizational data theft: possible misuse of contact details for phishing, exposure of employment or affiliation information, and, if financial or identity-related fields were present, elevated risk of fraud. Because the number of people affected and the specific data elements are unknown, the scale of personal harm cannot be quantified from the public record. People connected to the institution as staff, former staff, donors, members, students, or partners have the clearest reason to stay alert for unusual communications that reference the organization.
For the International Center of Photography itself, a ransomware-related data theft can mean operational disruption, cost of investigation and recovery, legal and notification obligations where personal data is involved, and reputational strain with supporters and the public. Cultural institutions often rely on trust and long-term relationships; even an unverified claim of internal-file theft can prompt questions from employees, funders, and partners until clearer facts emerge. None of these outcomes require assuming negligence; they follow from the nature of modern ransomware campaigns against organizations that hold concentrated internal records.
If your data was in this claimed breach
If you have a past or present connection to the International Center of Photography—employment, donation, membership, enrollment, or vendor relationship—treat unsolicited messages that cite the institution with caution. Prefer official channels you already trust when checking for updates. Consider monitoring financial accounts and credit reports for unfamiliar activity, and enable stronger authentication on email and other important accounts where you reuse credentials or personal details that an employer or cultural organization might have held.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step does not confirm or deny inclusion in this specific incident, but it can help you see whether your address appears in other publicly tracked breaches and prioritize password changes and monitoring accordingly. Keep records of any suspicious contact, and rely on verified notices from the organization rather than third-party claims alone.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Hinsdale School District Listed by medusa Ransomware GroupCampbell County Schools Listed by medusa Ransomware GroupThe Glendale Unified School District Listed by medusa Ransomware GroupGreat Valley School District Listed by medusa Ransomware GroupLatest breaches
Publicly posted by medusa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.