Medusa Ransomware Strikes Travel Alberta in Major Data Breach

Incident Date:

September 30, 2024

World map

Overview

Title

Medusa Ransomware Strikes Travel Alberta in Major Data Breach

Victim

Travel Alberta

Attacker

Medusa

Location

Calgary, Canada

, Canada

First Reported

September 30, 2024

Medusa Ransomware Group Targets Travel Alberta in Significant Data Breach

Travel Alberta, the official tourism organization for the province of Alberta, Canada, has become the latest victim of the Medusa ransomware group. The attack, which has been publicly claimed by Medusa on their dark web leak site, involves the exfiltration of approximately 799.80 GB of sensitive data. The group is demanding a ransom of $480,000 to prevent the public release of this data.

About Travel Alberta

Travel Alberta is a Crown corporation established by the Government of Alberta, operating under the Travel Alberta Act. With a workforce of around 125 employees, the organization is headquartered in Calgary. It plays a pivotal role in promoting Alberta as a premier travel destination, focusing on enhancing visitor experiences through comprehensive information on outdoor activities, cultural events, and urban attractions. The organization reported an annual revenue of $61 million, reflecting its significant impact on Alberta's tourism sector.

Vulnerabilities and Targeting

As a mid-sized organization with a substantial digital presence, Travel Alberta is inherently vulnerable to cyber threats. The nature of its operations, which involves handling large volumes of data related to tourism and visitor information, makes it an attractive target for ransomware groups like Medusa. The attack underscores the risks faced by organizations in the hospitality sector, which often rely on interconnected systems and digital platforms to manage their operations and engage with global audiences.

Attack Overview

The Medusa ransomware group has listed Travel Alberta on their data leak site, threatening to publish the stolen data within 9-10 days if their demands are not met. This tactic of public shaming and data exposure is a hallmark of Medusa's operations, designed to pressure victims into compliance. The group's demand for a $480,000 ransom highlights the financial stakes involved in such cyberattacks.

About Medusa Ransomware Group

Medusa emerged as a notable ransomware group in late 2022, operating as a Ransomware-as-a-Service platform. It distinguishes itself through its aggressive targeting of various sectors, including education, healthcare, and public services. Medusa's ransomware is known for its ability to disable security measures and encrypt critical data, making recovery efforts challenging. The group's global reach and sophisticated tactics have positioned it as a significant threat in the cybersecurity landscape.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.