LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Tonga Communications Listed by medusa Ransomware Group

HIGH severityUnverified claimHow we verify

Tonga Communications Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·February 11, 2023
Tonga Communications Listed by medusa Ransomware Group

Reported February 11, 2023.

HIGH
Severity
February 11, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Tonga Communications Listed by medusa Ransomware Group (reported February 11, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

For customers and staff of Tonga Communications, a listing on a ransomware group's leak site raises immediate questions about whether personal or account-related information has left the company's systems. Public reporting from February 11, 2023, states that the government-owned telecommunications provider was named by the group known as medusa, which claimed that internal files had been taken in a ransomware attack. The number of people affected remains unknown, and independent confirmation of the full scope has not been published in the available record.

That uncertainty matters in a small island nation where a single major telecom provider handles mobile, fixed-line and internet services for a large share of the population. Even limited exposure of internal material can create lasting practical problems for individuals who rely on the company for everyday connectivity and communications.

Breaking down the breach

According to the reported summary, Tonga Communications Corporation was listed by the medusa ransomware group on or around February 11, 2023. The group claimed that internal files were exfiltrated as part of a ransomware attack. No public figure has been given for the volume of data, the number of systems involved, or the precise date the intrusion began. The number of people affected is listed as unknown. Method of initial access, duration of presence inside the network, and whether encryption was also deployed have not been disclosed in the available facts. The listing itself constitutes a claim by the group rather than an independently verified confirmation of every asserted detail.

What is stated is limited to the organisation's identity, the reporting date, the attribution to medusa, and the description of internal files taken in a ransomware incident. Beyond those points, public detail remains sparse.

Inside medusa

Medusa is a known ransomware operation that has appeared repeatedly in public reporting since at least 2021. Like many contemporary groups, it typically follows a double-extortion model: data is copied from the victim's environment before systems are encrypted, and the group then threatens to publish the stolen material on a dedicated leak site if payment is not made. Listings on that site are used both as pressure on the victim and as advertising of the group's activity. Medusa has been associated with attacks across multiple sectors and geographies; its operators have historically favoured opportunistic targeting of organisations that hold operational or customer data of value.

In this case, the only specific claim tied to Tonga Communications is the leak-site listing and the assertion that internal files were exfiltrated. No further statements attributed to the group about this particular victim—such as sample file names, ransom demands, or deadlines—are present in the provided facts. Those broader patterns of medusa's public behaviour supply context for how such listings usually function, but they do not add verified particulars about the Tonga incident itself.

Who is Tonga Communications?

Tonga Communications Corporation is a government-owned telecommunications provider based in Nuku'alofa. It supplies mobile, fixed-line and internet services and is described as Tonga's leading cellular, fixed-line and internet provider. In a country of modest population and limited infrastructure alternatives, a national telecom operator sits at the centre of both everyday civilian communications and essential government and commercial connectivity.

Organisations of this type routinely manage customer account records, billing information, call-detail and usage data, network configuration material, employee records, and internal operational documents. A breach affecting such a provider is consequential because the same systems that keep the country connected also concentrate sensitive personal and operational information. Disruption or data exposure can therefore touch a wide cross-section of residents, businesses and public services that depend on the network.

What data was at risk

The available facts state only that internal files were exfiltrated in a ransomware attack. No inventory of specific data categories—customer names, identity numbers, financial details, call records, passwords, or employee information—has been published in the record. Exact contents therefore remain unconfirmed.

Telecommunications providers of this kind typically hold customer subscriber data, billing and payment records, service-usage information, network and infrastructure documentation, and internal corporate files. Any of those categories could theoretically have been among the material taken, yet that possibility is not established fact. Until a fuller accounting is released by the organisation or by independent investigators, the precise nature of the exposed files cannot be stated with certainty.

What's at stake

For individuals, the practical risks centre on misuse of any personal or account information that may have been included among the internal files. That can mean targeted phishing or social-engineering attempts that reference real account details, attempts to take over related online services, or longer-term identity-related fraud if identity documents or financial data were present. Because the scale and exact contents are unknown, people cannot yet gauge their individual exposure with precision.

For the organisation, the stakes include operational disruption, potential regulatory or contractual obligations, erosion of customer trust, and the cost of investigation and remediation. In a small market with few alternative providers, reputational damage and any prolonged service impact can affect national communications more broadly. None of these outcomes is automatic; they depend on what was actually taken and how the incident is handled going forward. The limited public detail simply means those questions remain open.

What to do if you're exposed

If you are a customer or employee of Tonga Communications, treat the situation as a prompt for basic hygiene rather than confirmed personal compromise. Monitor account statements and service notifications for unfamiliar activity. Change passwords on your telecom account and on any other services that reused the same credentials, preferably enabling multi-factor authentication where it is offered. Be cautious of unsolicited calls, messages or emails that claim to relate to the incident and ask for personal details or payments; verify any such contact through official company channels you already trust. Keep records of any suspicious contact.

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That step will not confirm or rule out involvement in this specific incident, but it can surface other exposures that warrant the same protective measures. Stay alert for any official updates from Tonga Communications that may clarify what data was involved and what further steps the company recommends.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyTonga Communications security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Tonga Communications’s full breach history →

More recent breaches

Skynet Listed by medusa Ransomware GroupAugust 30, 2023Comcast Listed by medusa Ransomware GroupSeptember 26, 2025Sun Direct Listed by medusa Ransomware GroupJune 13, 2025Waldner's Listed by play Ransomware GroupDecember 18, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Tonga Communications Listed by medusa Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by medusa — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram