LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › UnigazJordan Listed by medusalocker Ransomware Group

HIGH severityUnverified claimHow we verify

UnigazJordan Listed by medusalocker Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·May 30, 2025
UnigazJordan Listed by medusalocker Ransomware Group

Reported May 30, 2025.

HIGH
Severity
May 30, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

UnigazJordan has been listed by the medusalocker ransomware group, with internal files reported exfiltrated in an attack disclosed on May 30, 2025. Individuals connected to the organisation should review any recent notices and follow recommended steps if their information appears to have been exposed.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 30 May 2025 the ransomware group medusalocker publicly listed UnigazJordan, stating that it had carried out an attack in which internal files were taken from the organisation. The number of people whose information may be involved remains unknown, and the precise contents of the material have not been independently confirmed. For anyone connected to UnigazJordan—employees, contractors, customers or partners—the practical concern is straightforward: personal or operational data that was never meant to leave the company’s systems may now sit outside its control, creating risks of fraud, identity misuse or further targeting.

Public detail is limited to the group’s own claim. That claim, however, is enough to warrant careful attention from those who may be affected and from the organisation itself.

Inside the incident

According to the listing published by medusalocker, UnigazJordan (associated with the domain www.unigaz.net) suffered a ransomware attack in which internal files were exfiltrated. The group reported a figure of $690.6 million in connection with the organisation and stated that a list of the files is available via an external file-sharing link. No independent verification of the attack’s success, the volume of data taken, or the exact date of intrusion has been released. The number of individuals affected is recorded as unknown. Timing beyond the 30 May 2025 listing date, the method of initial access, and any ransom demand details remain undisclosed in the available record.

The listing itself constitutes an unverified claim by the threat actor. Organisations named on ransomware leak sites sometimes confirm the event later, sometimes dispute it, and sometimes remain silent; none of those outcomes has been established here.

Who is medusalocker?

Medusalocker is a ransomware operation that has been active for several years and is known for double-extortion tactics. After gaining access to a network, the group typically encrypts systems and simultaneously steals data, then threatens to publish the stolen material if a ransom is not paid. Listings on its dedicated leak site are used both to pressure victims and to advertise the group’s activity. Public reporting on prior campaigns shows that medusalocker has targeted organisations across multiple sectors and geographies, often focusing on mid-sized companies whose operational data or customer records can be leveraged for payment. The group’s claims about any specific victim, including UnigazJordan, should be treated as assertions until corroborated by the organisation or by independent forensic evidence.

About UnigazJordan

UnigazJordan operates in the energy and gas distribution sector in Jordan, supplying liquefied petroleum gas and related services to residential, commercial and industrial customers. Companies of this type routinely hold employee records, customer account details, billing information, supplier contracts, operational logs and technical documentation. A breach involving such an organisation can therefore touch both internal staff and the wider public who rely on its services. Because energy infrastructure and customer data intersect, any confirmed compromise carries consequences that extend beyond the company itself—disruption of service, exposure of personal identifiers, or the release of commercially sensitive material can all follow if the threat actor’s claims prove accurate.

The information in question

The only data type named in the available record is “internal files exfiltrated in ransomware attack.” No further breakdown—such as whether the files contain personal identifiers, financial records, technical schematics or correspondence—has been disclosed. Organisations in the gas distribution sector typically maintain employee personal data, customer contact and payment information, contractual documents and operational records. Whether any of those categories were among the material claimed by medusalocker remains unconfirmed. The group has stated that a list of files is available at an external link, but the actual contents of that list have not been independently examined or verified in the public record.

What's at stake

For individuals, the principal risks are identity theft, phishing or social-engineering attempts that exploit knowledge of their relationship with UnigazJordan, and potential misuse of any personal details that may have been present in the internal files. Even if only operational documents were taken, those documents can still reveal names, roles, contact details or account numbers that enable further fraud. For the organisation, the stakes include regulatory scrutiny, loss of customer trust, possible service disruption if systems remain encrypted, and the longer-term cost of investigation and remediation. Because the scale of the alleged exfiltration is unknown, the full extent of exposure cannot yet be measured; the uncertainty itself is a material risk that requires prompt, transparent handling.

If your data was in this claimed breach

If you have a past or present connection to UnigazJordan—as an employee, customer or contractor—treat the listing as a signal to increase vigilance. Monitor bank and credit-card statements for unfamiliar activity, enable multi-factor authentication on email and financial accounts, and be wary of unsolicited messages that reference the company or claim to offer help with a data incident. Change passwords that may have been reused across work and personal services. Keep records of any suspicious contact. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan does not confirm involvement in this specific incident but can reveal whether the address is circulating more widely. Official confirmation or further detail from UnigazJordan itself remains the most reliable source of guidance for those potentially affected.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyUnigazJordan security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See UnigazJordan’s full breach history →

More recent breaches

usenergy Listed by medusalocker Ransomware GroupSeptember 14, 2025dulay.ca Listed by medusalocker Ransomware GroupNovember 17, 2025Trimble Inc / Gerrard Inc Listed by medusalocker Ransomware GroupNovember 7, 2025Mulia Raya Listed by medusalocker Ransomware GroupMay 29, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the UnigazJordan Listed by medusalocker Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by medusalocker — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram