Mulia Raya Listed by medusalocker Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Mulia Raya has been added to a list published by the MedusaLocker ransomware group, with internal files reportedly taken during the attack. The incident came to light on 29 May 2025; anyone connected to the organisation should check whether their information was exposed and take any recommended protective steps.
On 29 May 2025, the organisation Mulia Raya was listed by the ransomware group known as medusalocker. Public reporting indicates the group claims to have carried out a ransomware attack that involved the exfiltration of internal files, with a reference to the organisation’s website www.muliaraya.co.id and a figure of $34.8 million, along with a link to a list of files. The number of people affected remains unknown, and independent confirmation of the full scope of the incident has not been published.
The listing itself is a claim made by the group on its leak site. For anyone connected to Mulia Raya—employees, partners, customers or others—the appearance of an organisation on a ransomware leak site raises practical questions about what information may have left its systems and what steps can reduce personal risk.
What happened
According to the available record, Mulia Raya was listed by medusalocker on 29 May 2025. The group asserts that internal files were exfiltrated during a ransomware attack. The listing references the organisation’s website www.muliaraya.co.id, a figure of $34.8 million, and states that a list of files is available at a provided link. No further verified details on the timing of the intrusion, the method of initial access, the total volume of data taken, or whether systems were encrypted have been disclosed in the public summary. The number of individuals affected is recorded as unknown.
Because the information originates from the threat actor’s own listing, it should be treated as an unverified claim until corroborated by the organisation or independent investigators. Public detail on the incident remains limited to the points above.
Who is medusalocker?
Medusalocker is a ransomware operation that has been active for several years and is documented in open-source reporting as using a double-extortion model. In typical campaigns the group encrypts systems and simultaneously steals data, then threatens to publish the stolen material on a dedicated leak site if a ransom is not paid. Listings on that site commonly include the victim’s name, website, a claimed ransom or valuation figure, and sometimes sample files or a file inventory.
The group has previously targeted organisations across multiple sectors and geographies. Its public communications are generally limited to the leak-site posts themselves; it does not usually issue detailed press statements about individual victims beyond the claims posted there. In this case, the only statements attributed to medusalocker concerning Mulia Raya are those contained in the listing: that internal files were allegedly exfiltrated and that a file list is available. No additional claims specific to this victim have been independently verified.
Mulia Raya and its sector
Mulia Raya is an organisation operating under the domain muliaraya.co.id. Public background on the precise nature of its business is limited in the breach record; organisations of this type in Indonesia commonly engage in commercial, trading or service activities and therefore hold a range of internal operational, financial and personnel records. Like most mid-sized enterprises, such entities typically maintain employee data, customer or supplier information, contracts, financial documents and internal correspondence.
A ransomware listing that claims the theft of internal files is consequential because those files can contain both business-sensitive material and personal data belonging to staff, partners or clients. Even when the exact contents remain unconfirmed, the mere assertion that internal files left the organisation’s control creates ongoing uncertainty for anyone whose information may have been stored there.
What data was at risk
The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory of data types—such as names, contact details, financial records or identity documents—has been publicly disclosed or independently confirmed. The listing mentions that a list of files is available via a third-party link, but the contents of that list have not been verified in the available record.
Organisations of Mulia Raya’s general profile typically hold employee records, payroll information, supplier and customer contracts, invoices, internal emails and operational documents. Whether any of those categories were among the files claimed by medusalocker is unconfirmed. Until the organisation or a competent authority publishes a clear statement, the exact nature of the exposed material should be regarded as unknown.
Why it matters
When internal files are claimed to have been stolen, the practical risks fall on both the organisation and the individuals whose data may be inside those files. For people, possible consequences include unwanted contact, phishing attempts that reference real internal details, or longer-term misuse of personal information if it later appears in other criminal marketplaces. For the organisation, the listing can disrupt operations, damage trust with partners and customers, and create regulatory or contractual obligations to investigate and notify affected parties.
Because the number of people affected is unknown and the precise data types remain undisclosed, the scale of personal impact cannot yet be measured. The $34.8 million figure appearing in the listing is part of the group’s claim and has not been independently explained; it may represent a ransom demand or another asserted valuation, but that interpretation is not confirmed. In any event, the core issue for affected individuals is the potential exposure of information that was never intended to leave Mulia Raya’s systems.
What to do if you're exposed
If you have a relationship with Mulia Raya—as an employee, former employee, customer, supplier or other contact—consider the following practical steps while further details remain limited:
- Monitor financial accounts and credit reports for unexpected activity and set up fraud alerts where available.
- Treat unsolicited emails, messages or calls that reference Mulia Raya or internal details with caution; verify any request through official channels before responding.
- Change passwords on accounts that may have been linked to the organisation and enable multi-factor authentication wherever possible.
- Keep records of any suspicious contact and report confirmed identity-related fraud to the relevant local authorities.
- Run a free exposure scan of your email address to check whether it has already appeared in known breach data sets; this can provide an early indication of wider circulation.
Public information about this incident is still sparse. Anyone who believes their data may have been involved should watch for official statements from Mulia Raya and follow guidance issued by Indonesian data-protection or cybersecurity authorities as it becomes available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
CEAGESP / Netfeirasp Listed by medusalocker Ransomware Groupdulay.ca Listed by medusalocker Ransomware GroupTrimble Inc / Gerrard Inc Listed by medusalocker Ransomware Groupusenergy Listed by medusalocker Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Mulia Raya Listed by medusalocker Ransomware Group →
Publicly posted by medusalocker — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.