Organon Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Organon was listed by the Medusa ransomware group on September 26, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone connected to the company should check for official notices and monitor their accounts.
On September 26, 2025, the pharmaceutical company Organon was listed by the Medusa ransomware group, which claimed responsibility for a ransomware attack involving the exfiltration of internal files totaling 478.2 GB. The number of people affected remains unknown, and public detail on the precise method, timing of the intrusion, or confirmation of the listing is limited.
This matters because Organon develops and markets prescription medicines used by patients worldwide. Any compromise of internal systems at a firm of this scale raises concrete questions about the security of operational data and the potential downstream risks to individuals whose information may have been held in those systems.
Inside the incident
According to the available record, Organon was listed by the Medusa ransomware group on September 26, 2025. The group claims that internal files were exfiltrated during a ransomware attack and that the total volume of data leakage amounts to 478.2 GB. No further public confirmation of the attack’s success, the exact date of intrusion, or the technical vector has been disclosed in the facts provided.
The number of individuals affected is listed as unknown. Beyond the claim of internal-file exfiltration and the stated data volume, specifics such as which systems were accessed, whether encryption was deployed on production environments, or whether any ransom demand was made remain undisclosed. The listing itself constitutes a claim by the group rather than independently verified evidence of the full scope of the incident.
Inside medusa
Medusa is a well-documented ransomware operation that has been active for several years. Public reporting consistently describes the group as employing a double-extortion model: operators encrypt victim systems while also exfiltrating data, then threaten to publish the stolen material on a dedicated leak site if payment is not received. Medusa typically posts victim names, sample file listings, and claimed data volumes on that site to increase pressure.
The group has previously targeted organizations across multiple sectors, including healthcare, manufacturing, and professional services. Its tactics commonly involve initial access through phishing, exploitation of unpatched remote-access services, or compromised credentials, followed by lateral movement and data staging before encryption. In this case, Medusa’s leak-site listing of Organon should be treated as an unverified claim; the facts do not state that the group’s assertions about the volume or content of the data have been independently confirmed.
Organon and its sector
Organon creates, manufactures, and markets innovative prescription medicines intended to improve health and quality of life. The company is headquartered at 30 Hudson Street, Jersey City, New Jersey 07302, USA, and employs approximately 10,000 people. Through a combination of internal innovation and business partnerships, it focuses on selected therapeutic fields.
As a pharmaceutical manufacturer and marketer, Organon operates in a highly regulated sector that routinely handles sensitive commercial, research, manufacturing, and supply-chain information. Organizations of this type also maintain employee records, partner contracts, and, in many cases, limited patient or healthcare-provider data related to product support and pharmacovigilance. A breach at such a firm is consequential because disruption or exposure can affect not only corporate operations but also the integrity of medicine supply chains and the privacy of individuals connected to those operations.
What data was at risk
The facts state that internal files were exfiltrated in the ransomware attack and that the total amount of data leakage claimed is 478.2 GB. No more granular inventory of file types, databases, or specific categories of personal information has been disclosed.
Pharmaceutical companies of Organon’s size typically hold a range of internal material: research and development documents, manufacturing process data, commercial contracts, employee human-resources files, and correspondence with healthcare partners. Whether any of those categories were among the claimed 478.2 GB remains unconfirmed. Public detail on exact contents is limited; therefore it is not possible to state with certainty which data elements, if any, belonging to employees, partners, or patients were exposed.
The real-world impact
For individuals whose information may have been present in the exfiltrated files, the primary risks include potential misuse of personal identifiers, employment details, or any health-related data that could facilitate phishing, identity fraud, or targeted social engineering. Because the precise contents are unconfirmed, the actual exposure level for any given person cannot yet be quantified.
For Organon itself, the incident carries operational, regulatory, and reputational consequences. Regulatory bodies overseeing pharmaceutical companies often require notification and investigation when personal or sensitive commercial data is compromised. Even if core manufacturing systems were unaffected, the claimed theft of internal files can disrupt partner relationships, invite scrutiny of security practices, and generate costs associated with forensic review, legal counsel, and potential remediation. The unknown number of affected individuals further complicates any coordinated response.
What to do if you're exposed
If you have a past or present relationship with Organon—as an employee, contractor, healthcare partner, or patient who has interacted with the company’s support programs—consider the following practical steps:
- Monitor financial and medical accounts for unusual activity and enable multi-factor authentication wherever available.
- Treat unsolicited emails, calls, or messages that reference Organon or pharmaceutical matters with heightened caution; verify any request through official channels.
- Request a free credit report or fraud alert if you believe personal identifiers may have been involved.
- Retain any official notifications you receive from Organon or regulators for reference.
- Run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets.
Public detail on this incident remains limited. Continued monitoring of official statements from Organon and relevant authorities is the most reliable way to learn whether additional confirmed information becomes available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
JBS Listed by medusa Ransomware GroupAtrium Living Centers Listed by medusa Ransomware GroupAdore Children and Family Services Listed by medusa Ransomware GroupInsightin Health Listed by medusa Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Organon Listed by medusa Ransomware Group →
Publicly posted by medusa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.