LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Safco International Gen Trading Listed by medusa Ransomware Group

HIGH severityUnverified claimHow we verify

Safco International Gen Trading Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·January 18, 2025
Safco International Gen Trading Listed by medusa Ransomware Group

Reported January 18, 2025.

HIGH
Severity
January 18, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Safco International Gen Trading was listed by the Medusa ransomware group on January 18, 2025, after internal files were exfiltrated in a ransomware attack. The number of people affected has not been disclosed; anyone who has shared data with the company should review their accounts and monitor for suspicious activity.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People who work with or for Safco International Gen Trading, or who appear in its business records, may now face the practical risk that internal company material has left the organisation’s control. When a ransomware group lists a firm and claims a large volume of files has been taken, the immediate concern for ordinary individuals is whether names, contact details, contracts or other personal information could be among what was removed, and what that could mean for identity misuse or unwanted contact later.

Public reporting on 18 January 2025 states that Safco International Gen Trading has been listed by the medusa ransomware group, which claims to have exfiltrated internal files amounting to 506.9 GB. The number of people affected remains unknown, and independent confirmation of the full scope is not available in the disclosed material.

Inside the incident

According to the available record, Safco International Gen Trading was listed by the medusa ransomware group on or around 18 January 2025. The group claims that internal files were exfiltrated in a ransomware attack and that the total volume of data involved is 506.9 GB. No further public detail has been provided on the precise date of intrusion, the initial access method, whether systems were encrypted, or whether any ransom demand was made or paid. The number of individuals whose information may be contained in the material is listed as unknown. These points remain unconfirmed beyond the group’s listing and the reported summary.

What is stated is limited to the claim of exfiltration of internal files and the stated data volume. No inventory of specific file names, systems, or categories beyond “internal files” has been released in the facts at hand. Readers should therefore treat the listing as an unverified claim by the threat actor until more is independently established.

Who is medusa?

Medusa is a known ransomware operation that has appeared in public reporting for several years. Groups of this type typically gain access to an organisation’s network, move laterally, and copy large volumes of data before encrypting systems or simply threatening to publish the stolen material if a ransom is not paid. This double-extortion model—theft plus the threat of leak—has become common among ransomware actors. Medusa has been associated with leak-site postings that name victims and sometimes display sample files or volume claims to pressure payment.

Public knowledge of the group’s broader activity does not, by itself, prove every detail of any single listing. In this case the facts record only that medusa has listed Safco International Gen Trading and claims 506.9 GB of internal files were taken. No additional statements attributed specifically to medusa about this victim appear in the provided record, so nothing further should be assumed.

Who is Safco International Gen Trading?

Safco International Gen Trading is described as a company based in the United Arab Emirates that produces food and supplies the FoodService and HoReCa (hotel, restaurant and catering) sector both inside the UAE and abroad. Its corporate office is located in Dubai Investment Park II, Dubai, and the organisation is reported to have 543 employees. Firms of this kind sit in the middle of supply chains: they handle product specifications, customer and supplier contacts, logistics, invoices, and internal operational records.

A breach involving such an organisation matters because food-service suppliers routinely hold commercial and personal data that can be useful to fraudsters or competitors. Employee records, partner lists, and contractual documents are typical holdings for a mid-sized trading and manufacturing business of this profile. The listing therefore raises questions not only for the company but for anyone whose details sit in its systems.

The information in question

The facts name the exposed material as “internal files exfiltrated in ransomware attack” and state a total volume of 506.9 GB. No further breakdown of data types—such as employee personal data, customer lists, financial records, or product formulas—is provided. The number of people affected is explicitly unknown.

Organisations in food production and HoReCa supply commonly hold employee contact and payroll information, supplier and customer commercial data, shipping and quality records, and internal correspondence. Whether any of those categories are present in the claimed 506.9 GB remains unconfirmed. Until a fuller disclosure or independent analysis appears, the exact contents should be treated as unknown.

Why it matters

For individuals, the practical risk is that personal or contact information, if present in the taken files, could be used for phishing, social-engineering calls, or identity-related fraud. Even commercial documents can contain names, phone numbers, email addresses and signatures that later appear in scam campaigns. Because the scale of personal impact is unknown, people connected to Safco—employees, former staff, suppliers or customers—cannot yet rule themselves out.

For the organisation, the consequences include potential regulatory scrutiny under applicable data-protection rules, disruption of supplier and customer relationships, and the cost of investigation and remediation. A claimed volume of more than 500 GB is large enough to contain years of operational material; if authentic, that volume alone can prolong the period during which sensitive information remains at risk of further misuse. None of this establishes fault; it simply describes the ordinary stakes when internal files leave an organisation’s control.

What to do if you're exposed

If you have a past or present connection to Safco International Gen Trading, treat the situation as a prompt for basic hygiene rather than panic. Monitor bank and credit activity for unexpected accounts or charges. Be wary of unsolicited emails or calls that reference the company or claim to need urgent verification of details. Change passwords on any accounts that reused credentials tied to work email, and enable multi-factor authentication where available. If you receive a notification from the company itself, follow the official guidance it provides.

You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Such a check does not confirm or deny involvement in this specific incident, but it can show whether your details are circulating more widely and help you prioritise further steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySafco International Gen Trading security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Safco International Gen Trading’s full breach history →

More recent breaches

Callipo Group Listed by medusa Ransomware GroupDecember 17, 2025Sampoerna Agro Listed by medusa Ransomware GroupDecember 13, 2025FDC Interiors Listed by medusa Ransomware GroupNovember 17, 2025Alissa Group Listed by medusa Ransomware GroupOctober 22, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Safco International Gen Trading Listed by medusa Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by medusa — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram