Simon Property Group Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Simon Property Group was listed by the medusa ransomware group on October 28, 2025, after internal files were exfiltrated. Individuals should check whether their information was exposed and take appropriate protective steps.
Ransomware groups continue to target large real-estate and retail operators, treating them as high-value sources of internal records and operational data. In this environment, a listing on a known leak site can signal that an organization has been hit by double-extortion tactics even when full technical details remain scarce.
On 28 October 2025 Simon Property Group, a major U.S. real-estate investment trust, appeared on the leak site operated by the medusa ransomware group. The listing claims that internal files were exfiltrated during a ransomware attack. The number of people affected is unknown, and public detail beyond the group’s claim is limited. The incident matters because the company manages high-traffic shopping destinations that handle substantial volumes of business, employee and visitor information.
What happened
Public reporting states that Simon Property Group was listed by the medusa ransomware group on 28 October 2025. According to the available summary, the group asserts that internal files were exfiltrated in a ransomware attack. No further confirmed information has been released about the precise date of intrusion, the initial access method, the volume of data taken, or whether systems were encrypted. The number of individuals potentially affected remains unknown. The only concrete claim available is the leak-site listing itself; independent verification of the group’s assertions has not been published.
The group behind it: medusa
Medusa is a ransomware operation that has been active for several years and is widely documented in public threat-intelligence reporting. Like many contemporary groups, it typically employs a double-extortion model: data are stolen before encryption, and the operators threaten to publish the material on a dedicated leak site if a ransom is not paid. The group has previously claimed responsibility for attacks against organizations across multiple sectors, often posting sample files or directory listings to pressure victims. Its leak site functions as both a negotiation channel and a public shaming tool. In the present case the group claims that Simon Property Group’s internal files were taken; that claim has not been independently confirmed in the available record.
Who is Simon Property Group?
Simon Property Group is a leading real-estate investment trust headquartered in Indianapolis, Indiana. Founded in 1993 and led by CEO David E. Simon, the company owns, develops and manages premier shopping malls, outlet centers and lifestyle destinations across the United States and internationally. Its well-known brands include Premium Outlets and The Mills centers. These properties attract millions of visitors each year and combine retail, dining and entertainment offerings. As a publicly traded REIT, the organization maintains extensive operational, financial, tenant and employee records. A breach of such an entity is consequential because the data it holds can include commercially sensitive contracts, employee personal information and, potentially, limited customer or visitor records generated by its large physical footprint.
What was likely exposed
The only data type named in the available facts is “internal files” said to have been exfiltrated. No inventory of those files, no file counts and no specific categories such as employee records, tenant contracts or financial documents have been disclosed. Organizations of this type typically store employee personally identifiable information, payroll and benefits data, lease agreements, vendor contracts, financial statements and operational documents related to property management. Whether any of those categories were among the files claimed by medusa remains unconfirmed. Public detail is limited to the group’s assertion that internal files were taken.
What's at stake
For individuals whose information may have been among the exfiltrated files, the practical risks include potential identity theft, phishing campaigns that reference authentic internal details, and unauthorized use of personal or employment data. Employees and contractors could face targeted social-engineering attempts. For the organization itself, the stakes include possible regulatory scrutiny, contractual obligations to notify affected parties, reputational damage among tenants and investors, and the operational cost of investigation and remediation. Because the exact contents and scale remain undisclosed, the full extent of these risks cannot yet be quantified. The listing alone, however, creates ongoing uncertainty for anyone whose data the company may hold.
What to do if you're exposed
If you are a current or former employee, contractor or business partner of Simon Property Group, monitor financial accounts and credit reports for unusual activity and consider placing a fraud alert or credit freeze with the major credit bureaus. Be alert to unsolicited emails or calls that reference company-specific details. Change passwords on any accounts that may have reused credentials associated with work systems, and enable multi-factor authentication wherever possible. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Official notifications, if required, will come directly from the company or its authorized representatives; treat any unsolicited ransom or “help” messages with caution.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
LEVEL Listed by desolator Ransomware GroupTrindel Insurance Fund Listed by medusa Ransomware GroupMcFarland Commercial Insurance Services Listed by medusa Ransomware GroupJBS Listed by medusa Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Simon Property Group Listed by medusa Ransomware Group →
Publicly posted by medusa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.