LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Seznam Listed by Medusalocker Ransomware Group

HIGH severityUnverified claimHow we verify

Seznam Listed by Medusalocker Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 23, 2026
Seznam Listed by Medusalocker Ransomware Group

Reported September 23, 2026.

HIGH
Severity
September 23, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Seznam was listed by the Medusalocker ransomware group on 23 September 2026; the group claims to hold data belonging to an undisclosed number of people. Anyone who may have shared personal information with the company is advised to monitor their accounts and consider protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A ransomware group has publicly named Seznam on its leak site, raising practical questions for anyone who uses seznam.cz services or has shared personal or business contact details with the company. As of writing, Seznam has not publicly confirmed the claim, and independent verification is not reflected in the material available here. What is known is limited to the group's listing and a brief associated summary; the number of people who might be affected is unknown, and the types of data involved are not disclosed in that material.

For ordinary users, the stakes are conditional. If any personal information were later shown to have been copied, the usual risks would include unwanted contact, phishing that exploits familiarity with a well-known Czech brand, and longer-term misuse of email addresses or related identifiers. Until more is established, the listing itself is best treated as an unverified claim rather than proof that specific accounts or files are in circulation.

What is being claimed

Medusalocker has listed Seznam on its leak site. The listing was reported on September 23, 2026. According to the reported summary tied to that listing, the organization is associated with 115 emails extracted, and the domain referenced is seznam.cz. The group has not, in the facts provided, published a confirmed count of affected individuals, a full inventory of file types, a description of how access was supposedly obtained, or a timeline of alleged intrusion and exfiltration.

Public detail is therefore narrow. The headline framing is that Seznam appears on the group's site; the summary language refers to emails extracted in connection with the organization. No further technical method, ransom demand figure, or sample file set is included in the facts at hand. Seznam has not publicly stated the incident as of writing, so the listing remains an accusation by the group rather than an established breach record.

Inside Medusalocker

Medusalocker is a name associated in public reporting with ransomware operations that encrypt systems and pressure victims by threatening to publish stolen data. Groups in this category commonly maintain leak sites where they name organizations, post countdown-style pressure, and sometimes release samples or larger archives if they say negotiations failed. Their business model depends on fear of exposure as much as on locked machines: listing a recognizable brand is itself a form of leverage.

Well-documented patterns for such crews include opportunistic initial access, attempts to move laterally inside networks, theft of data before or alongside encryption, and public shaming when payment is refused or talks stall. None of that general pattern proves what happened in any single case. For this Seznam listing specifically, the facts state only that the group has named the organization, that the report date is September 23, 2026, and that the associated summary mentions 115 emails extracted and the seznam.cz domain. Claims beyond that—about tools used, duration of access, or the full scope of any alleged theft—are not established in the material provided and should not be inferred from the group's marketing alone.

About Seznam

Seznam is a major Czech internet company best known for consumer-facing online services under the seznam.cz domain, including search, email, news, and related digital products used widely in the Czech Republic. Organizations of this kind sit at the center of everyday digital life: people register accounts, store messages, save preferences, and interact with advertising and content systems that necessarily process identity and contact data.

A leak-site listing that names such a firm is consequential because of scale and trust, not because the listing has been proven. Millions of users may rely on a national portal for mail and information; partners and small businesses may use related tools. Even an unverified claim can prompt concern, support load, and speculative fraud attempts that trade on the brand name. That does not mean a breach has been confirmed—only that the audience for any real incident, if one were later substantiated, would be large and ordinary rather than niche.

What data was at risk

The facts do not disclose specific data types as exposed. The reported summary refers to 115 emails extracted in connection with the organization and names the seznam.cz domain; it does not inventory customer databases, message contents, passwords, payment details, identity documents, or internal corporate files. Exact contents therefore remain unconfirmed.

If files were taken from a company in this sector, firms that run large consumer portals and email services typically hold account identifiers, email addresses, profile information, service logs, and business contact data, and they may process additional personal information depending on the product. Those are sector norms, not a statement of what Medusalocker actually obtained. The group's own description of haul size or file categories, when it appears on a leak site, is attacker messaging and is not an audited inventory. Readers should treat any later dump claims the same way: as allegations until corroborated by the company, a regulator, or other independent evidence.

The real-world impact

For people who use Seznam services, impact depends on whether personal data was actually copied and what fields it contained—points that are not settled here. If email addresses alone were involved, common follow-on harms include targeted phishing, credential-stuffing attempts against other sites where the same address is a username, and scam messages that impersonate Seznam or Czech institutions. If richer profile or message-related data were ever shown to be included, risks could extend to social engineering that references real relationships or past correspondence. None of that should be read as confirmation that such data left Seznam's control.

For the organization, a public listing can mean reputational pressure, customer inquiries, and the operational cost of investigating and communicating—even when the underlying claim is disputed or incomplete. Extortion crews design listings to force exactly that pressure. What a leak-site entry does establish is that a named group chose to associate Seznam with its brand of threat. What it does not establish is negligence, confirmed theft, or a verified headcount of affected users. People affected remain unknown in the facts provided; speculation about internal security culture or engineering priorities is not supported by an unconfirmed listing and is not offered here.

If your data was involved

If you use a seznam.cz address or related Seznam accounts and are concerned, take calm, practical steps without assuming the worst. Change passwords on Seznam and on other important accounts if you reuse credentials; enable multi-factor authentication where available; treat unexpected messages that reference this listing or urge urgent payment or “verification” as likely scams. Monitor bank and important account activity in the normal way. If you later receive notice from Seznam or a regulator, follow that official guidance.

You can also run a free exposure scan of your email to check whether your information has already surfaced in known breach data sets unrelated to this claim. That kind of check does not prove or disprove Medusalocker's listing, but it can show whether your address appears in previously documented leaks and help you prioritize password and security hygiene. Remain skeptical of anyone selling “full dumps” or demanding fees to “remove” your name; those offers are often fraudulent. Official confirmation, if it comes, should come from Seznam or competent authorities—not from the group that posted the claim.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySeznam security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Seznam’s full breach history →

More recent breaches

Aokkef Listed by Medusalocker Ransomware GroupSeptember 23, 2026Abv Listed by Medusalocker Ransomware GroupSeptember 23, 2026Praveg Caves Jawai Listed by Medusalocker Ransomware GroupSeptember 12, 2026Frisby Roofing (Frisby Construction LLC) Listed by Medusalocker Ransomware GroupSeptember 12, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Seznam Listed by Medusalocker Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by medusalocker — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram