International University of Sarajevo Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
International University of Sarajevo was listed by the Medusa ransomware group on November 4, 2024, after internal files were exfiltrated in a ransomware attack. Individuals who may have had records with the university should verify their exposure and follow any guidance issued by the institution.
When a university appears on a ransomware group's leak site, the practical concern for students, staff and alumni is straightforward: personal and institutional records may have left the organisation's control. For the International University of Sarajevo, listed by the group known as medusa, the number of people affected remains unknown and the precise contents of any taken files have not been publicly itemised. What is known is limited, yet the listing itself raises real questions about privacy, identity risk and operational continuity for a community that spans dozens of countries.
Public reporting places the listing on 4 November 2024. Beyond that date and the claim of internal-file exfiltration, confirmed detail is scarce. Anyone connected to the university therefore faces uncertainty rather than a clear inventory of what, if anything, may have been exposed.
Inside the incident
According to available reporting, the International University of Sarajevo was listed by the medusa ransomware group on 4 November 2024. The group claims that internal files were exfiltrated in a ransomware attack. No public confirmation of the attack method, the volume of data, the exact date of intrusion, or any ransom demand has been released. The number of people affected is recorded as unknown. No independent verification of the listing or of successful data publication has been supplied in the material available for this account. In short, the incident is known primarily through the group's claim and the subsequent public notice; technical and forensic particulars remain undisclosed.
The group behind it: medusa
Medusa is a ransomware operation that has been active in recent years and is widely documented as employing double-extortion tactics. In such campaigns the operators typically encrypt systems while also copying data, then threaten to publish the stolen material on a dedicated leak site if payment is not made. The group has previously listed organisations across education, healthcare, manufacturing and public sectors. Listings on its site function as pressure tools and as public claims; they do not by themselves constitute independent proof that every asserted file set was taken or later released. For this incident the only assertion on record is the listing itself and the statement that internal files were exfiltrated. No further statements attributed specifically to medusa about the International University of Sarajevo appear in the reported facts.
International University of Sarajevo and its sector
The International University of Sarajevo is a private university founded in 2004 and located in Sarajevo, Bosnia and Herzegovina. It enrols approximately 1 650 students drawn from 55 countries and employs faculty from 20 countries; its corporate office is recorded at 15 Hrasnika Cesta with a staff of 263. Higher-education institutions routinely manage student academic records, staff employment files, financial and scholarship data, research materials, and identity documents required for enrolment and visas. Because the university serves an international population, the data it holds often cross multiple jurisdictions and may include sensitive personal identifiers. A ransomware claim against such an organisation therefore carries consequences that extend beyond a single campus: affected individuals may live or work far from Sarajevo, and institutional reputation and continuity of teaching and research can be disrupted even when the full scope of any breach stays unconfirmed.
The information in question
The reported facts state only that internal files were exfiltrated in a ransomware attack. No further breakdown of data types—such as student records, employee details, financial information or research materials—has been disclosed. Organisations of this kind typically hold enrolment forms, contact details, academic transcripts, payroll and contract information, and various administrative documents. Whether any of those categories were among the files claimed by medusa remains unconfirmed. Readers should therefore treat the precise contents as unknown rather than assume any specific category of personal data has been verified as exposed.
What's at stake
For individuals, the principal risks are identity misuse, phishing that leverages accurate personal details, and longer-term privacy erosion if records later appear in criminal markets. Students and staff from many countries may face differing legal protections and recovery options depending on where they reside. For the university, operational disruption, regulatory scrutiny under applicable data-protection rules, and the cost of investigation and remediation are the immediate organisational concerns. Because the scale of any compromise is unreported, both the personal and institutional stakes remain difficult to quantify with precision; the absence of confirmed numbers does not eliminate the need for vigilance.
What to do if you're exposed
If you have a past or present connection to the International University of Sarajevo, treat the listing as a prompt for basic protective steps rather than proof of personal compromise. Concrete actions include:
- Monitor bank and credit accounts for unfamiliar activity and enable available fraud alerts.
- Change passwords on university-related and personal accounts, using unique credentials and multi-factor authentication where offered.
- Be alert to phishing messages that reference the university, enrolment, or employment details; verify any request through official channels before responding.
- Request a free exposure scan of your email address to check whether that address has already appeared in known breach data sets.
- Retain copies of any official notices you receive from the university and follow guidance issued by its administration or by local data-protection authorities.
Public detail on this incident remains limited. Continued monitoring of official university statements is the most reliable way to learn whether further information about affected data or remedial measures becomes available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Broker Educational Sales & Training Listed by medusa Ransomware GroupAlbion College Listed by medusa Ransomware GroupSpirit Lake Community School District Listed by medusa Ransomware GroupInner City Education Foundation Listed by medusa Ransomware GroupLatest breaches
Publicly posted by medusa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.