SILKNET COMPANY Listed by medusalocker Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Silknet Company was listed by the MedusaLocker ransomware group on November 26, 2024, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; readers should check any Silknet Company notices and change passwords or enable additional security steps if they have accounts or data with the company.
On 26 November 2024, SILKNET COMPANY appeared on a leak site operated by the MedusaLocker ransomware group. Public reporting indicates the group claims to have conducted a ransomware attack that involved the exfiltration of internal files. The number of people affected remains unknown, and independent confirmation of the full scope of the incident has not been published. The listing is significant because Silknet operates major telecommunications services in Georgia, meaning any compromise of corporate or customer records could affect a wide range of individuals and businesses that rely on its networks.
Details released so far rest primarily on the group’s own claims. Those claims describe large volumes of data placed on sale, including corporate email material, customer information and audit records. Until Silknet or independent investigators provide further verification, the precise scale and contents of any breach stay unconfirmed.
Breaking down the breach
According to the available record, SILKNET COMPANY was listed by MedusaLocker on 26 November 2024. The group asserts that internal files were exfiltrated during a ransomware attack. Public detail on the timing of the intrusion, the initial access method, or the duration of any dwell time has not been disclosed. No official statement from the company confirming or denying the claims has been included in the source material.
The MedusaLocker listing further claims that more than 3 TB of data is involved, with a company email base of approximately 1 TB, customer data, company audit material for 2023/24, corporate records, passports and other information offered for sale at a price of $800 000. The listing also references the domains silknet.com and geocell.ge. These figures and descriptions originate solely from the threat actor’s publication; they have not been independently verified in the provided facts. The number of individuals whose data may be involved remains unknown.
The group behind it: medusalocker
MedusaLocker is a ransomware operation that has been active for several years and is documented in public cybersecurity reporting. The group typically employs a double-extortion model: encrypting systems while also stealing data and threatening to publish or sell it if a ransom is not paid. Affiliates often gain initial access through phishing, compromised remote-access services or unpatched vulnerabilities, then move laterally to locate high-value files before deploying the ransomware payload.
MedusaLocker has previously listed organisations across multiple sectors on its leak site, using the threat of public exposure to pressure victims. In this case the group claims SILKNET COMPANY data is available for purchase. No additional statements attributed specifically to MedusaLocker about this victim, beyond the listing itself, appear in the source facts. As with other ransomware claims, the listing should be treated as an unverified assertion until corroborated by the organisation or forensic investigators.
About SILKNET COMPANY
SILKNET COMPANY is a major telecommunications provider operating in Georgia. It offers fixed-line, mobile, broadband and related digital services under brands that include Geocell. Organisations of this type routinely maintain large volumes of customer account information, billing records, network infrastructure data, employee records and internal corporate documentation. Because telecommunications firms sit at the centre of everyday communications and commerce, a breach of their systems can have wide practical consequences for both private individuals and business customers.
Public records associate Silknet with the domains silknet.com and geocell.ge, which appear in the MedusaLocker listing. The company’s role as a national-scale service provider means that any confirmed compromise of customer or corporate data would be consequential for privacy, service continuity and regulatory compliance in its operating market.
What was likely exposed
The source facts state that internal files were exfiltrated in a ransomware attack. The MedusaLocker listing claims the material offered for sale includes a company email base of about 1 TB, customer data, company audit records for 2023/24, more than 3 TB of data overall, corporate information, passports and other records, with an asking price of $800 000. These specific categories and volumes are assertions made by the group; they have not been independently confirmed.
Exact contents therefore remain unconfirmed. Organisations in the telecommunications sector typically hold customer names, contact details, account identifiers, billing histories, service usage records, employee personal data, internal financial and audit documents, and sometimes identity documents required for account verification. Whether any or all of these categories were present in the claimed data set cannot be established from the available facts alone. Readers should treat the group’s inventory as a claim rather than verified fact.
The real-world impact
If the claimed data were authentic and subsequently circulated, affected individuals could face risks of phishing, identity fraud or unsolicited contact that exploits personal or account details. Corporate email archives, if genuine, might enable further social-engineering attacks against employees or partners. Audit and internal corporate files could expose sensitive business information. Because the number of people affected is unknown and the precise data types remain unverified, the actual scale of personal harm cannot yet be quantified.
For the organisation itself, a ransomware incident of this nature typically brings operational disruption, potential regulatory scrutiny under data-protection rules, and the need for forensic investigation, system recovery and customer notification. Even when claims are later shown to be exaggerated, the mere listing can damage trust and require substantial response resources. Until Silknet publishes its own findings, the concrete impact on customers and the company stays partially opaque.
Were you affected?
If you are a current or former customer, employee or partner of SILKNET COMPANY or its Geocell brand, treat any unexpected communications that reference the company with caution. Monitor account statements and credit activity for unusual behaviour, enable multi-factor authentication on email and financial services where available, and consider changing passwords that may have been reused. Official notifications, if any are issued by the company, should be followed carefully.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Such checks do not confirm involvement in this specific incident, but they provide a practical starting point for understanding whether your information has surfaced elsewhere. Stay alert for further statements from Silknet or competent authorities as more verified information becomes available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
CourtSmart Listed by medusalocker Ransomware Groupbendixengineering Listed by medusalocker Ransomware GroupSHAMASS.ORG Listed by medusalocker Ransomware GroupSgs Gmbh Listed by medusalocker Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the SILKNET COMPANY Listed by medusalocker Ransomware Group →
Publicly posted by medusalocker — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.