LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Simon Property Group Listed by medusa Ransomware Group

HIGH severityUnverified claimHow we verify

Simon Property Group Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 28, 2025
Simon Property Group Listed by medusa Ransomware Group

Reported October 28, 2025.

HIGH
Severity
October 28, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Simon Property Group was listed by the medusa ransomware group on October 28, 2025, after internal files were exfiltrated. Individuals should check whether their information was exposed and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target large real-estate and retail operators, treating them as high-value sources of internal records and operational data. In this environment, a listing on a known leak site can signal that an organization has been hit by double-extortion tactics even when full technical details remain scarce.

On 28 October 2025 Simon Property Group, a major U.S. real-estate investment trust, appeared on the leak site operated by the medusa ransomware group. The listing claims that internal files were exfiltrated during a ransomware attack. The number of people affected is unknown, and public detail beyond the group’s claim is limited. The incident matters because the company manages high-traffic shopping destinations that handle substantial volumes of business, employee and visitor information.

What happened

Public reporting states that Simon Property Group was listed by the medusa ransomware group on 28 October 2025. According to the available summary, the group asserts that internal files were exfiltrated in a ransomware attack. No further confirmed information has been released about the precise date of intrusion, the initial access method, the volume of data taken, or whether systems were encrypted. The number of individuals potentially affected remains unknown. The only concrete claim available is the leak-site listing itself; independent verification of the group’s assertions has not been published.

The group behind it: medusa

Medusa is a ransomware operation that has been active for several years and is widely documented in public threat-intelligence reporting. Like many contemporary groups, it typically employs a double-extortion model: data are stolen before encryption, and the operators threaten to publish the material on a dedicated leak site if a ransom is not paid. The group has previously claimed responsibility for attacks against organizations across multiple sectors, often posting sample files or directory listings to pressure victims. Its leak site functions as both a negotiation channel and a public shaming tool. In the present case the group claims that Simon Property Group’s internal files were taken; that claim has not been independently confirmed in the available record.

Who is Simon Property Group?

Simon Property Group is a leading real-estate investment trust headquartered in Indianapolis, Indiana. Founded in 1993 and led by CEO David E. Simon, the company owns, develops and manages premier shopping malls, outlet centers and lifestyle destinations across the United States and internationally. Its well-known brands include Premium Outlets and The Mills centers. These properties attract millions of visitors each year and combine retail, dining and entertainment offerings. As a publicly traded REIT, the organization maintains extensive operational, financial, tenant and employee records. A breach of such an entity is consequential because the data it holds can include commercially sensitive contracts, employee personal information and, potentially, limited customer or visitor records generated by its large physical footprint.

What was likely exposed

The only data type named in the available facts is “internal files” said to have been exfiltrated. No inventory of those files, no file counts and no specific categories such as employee records, tenant contracts or financial documents have been disclosed. Organizations of this type typically store employee personally identifiable information, payroll and benefits data, lease agreements, vendor contracts, financial statements and operational documents related to property management. Whether any of those categories were among the files claimed by medusa remains unconfirmed. Public detail is limited to the group’s assertion that internal files were taken.

What's at stake

For individuals whose information may have been among the exfiltrated files, the practical risks include potential identity theft, phishing campaigns that reference authentic internal details, and unauthorized use of personal or employment data. Employees and contractors could face targeted social-engineering attempts. For the organization itself, the stakes include possible regulatory scrutiny, contractual obligations to notify affected parties, reputational damage among tenants and investors, and the operational cost of investigation and remediation. Because the exact contents and scale remain undisclosed, the full extent of these risks cannot yet be quantified. The listing alone, however, creates ongoing uncertainty for anyone whose data the company may hold.

What to do if you're exposed

If you are a current or former employee, contractor or business partner of Simon Property Group, monitor financial accounts and credit reports for unusual activity and consider placing a fraud alert or credit freeze with the major credit bureaus. Be alert to unsolicited emails or calls that reference company-specific details. Change passwords on any accounts that may have reused credentials associated with work systems, and enable multi-factor authentication wherever possible. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Official notifications, if required, will come directly from the company or its authorized representatives; treat any unsolicited ransom or “help” messages with caution.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanySimon Property Group security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Simon Property Group’s full breach history →

More recent breaches

LEVEL Listed by desolator Ransomware GroupAugust 31, 2025Trindel Insurance Fund Listed by medusa Ransomware GroupMay 12, 2025McFarland Commercial Insurance Services Listed by medusa Ransomware GroupApril 8, 2025JBS Listed by medusa Ransomware GroupDecember 23, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Simon Property Group Listed by medusa Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by medusa — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram