MedusaLocker Lists ABV.BG as an Alleged Victim: What Is Confirmed and What Remains Unclear
What Happened
The MedusaLocker ransomware group listed ABV.BG among its alleged victims on September 23, 2026.
The case has been tracked by ransomware intelligence platforms including SOCRadar, where ABV.BG is marked with a Claimed status. According to the published information, the group claims it obtained access to data associated with the service.
That does not automatically mean a confirmed breach.
At this stage, there is no independent public confirmation that MedusaLocker accessed ABV.BG’s core infrastructure, encrypted systems or exfiltrated user mailboxes.
What Is Confirmed So Far
What can be confirmed is that MedusaLocker published the claim.
What remains publicly unclear is:
- how initial access may have been obtained;
- whether a specific vulnerability was exploited;
- which systems may have been affected;
- whether actual user data was exfiltrated;
- whether systems were encrypted;
- the true scope of any potential incident.
This distinction matters. A ransomware leak-site post is an investigative signal, but it does not by itself prove the technical details of a breach.
Why This Matters
For an email platform, the potential risk goes beyond ransomware.
Even limited access to accounts, credentials or contact information could support follow-on phishing, account takeover, recovery abuse or attacks against other services where passwords have been reused.
For business users, the impact can be broader. A compromised mailbox can be used for invoice fraud, impersonation of trusted partners or BEC (Business Email Compromise).
What Organizations Should Check
Regardless of whether this specific claim is ultimately confirmed, the case is a useful reminder to review:
- whether employees reuse passwords across services;
- whether MFA (Multi-Factor Authentication) is enabled where available;
- whether unusual sign-ins and new devices are monitored;
- whether email forwarding rules are reviewed;
- whether there is a process for rapid credential reset;
- whether employees are prepared for follow-on phishing that references a real incident.
Users should be particularly cautious with messages asking them to “verify the account,” “reset the password” or “confirm whether they were affected” if those messages lead to unfamiliar domains.
DIAMATIX Comment
From the DIAMATIX perspective, this case illustrates why a threat intelligence signal and a confirmed incident are not the same thing.
When a ransomware group lists an organization as a victim, the claim should neither be ignored nor automatically treated as proven.
The correct response is to examine logs, account activity, administrative actions, unusual data transfers and other indicators of compromise.
SOC (Security Operations Center) and MDR (Managed Detection and Response) processes provide this context: whether compromise actually occurred, what may have been affected and what response is required.
DIAMATIX helps organizations validate threat signals, investigate indicators of compromise and improve readiness for ransomware and identity-based attacks.
Request an exposure and response readiness review with DIAMATIX.
Sources
- SOCRadar — ABV.BG / MedusaLocker ransomware intelligence
- e-security.bg — MedusaLocker claim involving ABV.BG






