ATCO Ltd in Canada reported a ransomware incident attributed to the medusalocker threat actor, with 80 emails reportedly extracted and targeted via mail.gmail.com. The impacted country is #Canada
Incident Details
- Victim: ATCO Ltd
- Sector: Energy & Utilities
- Country: CA
- Actor: medusalocker
- Source: http://t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion/company/baravaj/
- Discovered: 2026-09-28T10:59:30.614815+00:00
- Published: 2026-09-28T10:59:17.243014+00:00
Information
- ATCO Ltd was targeted by MedusaLocker in Canada.
- 80 email addresses were extracted from the organization.
- The domain involved was mail.gmail.com.

Disclaimer: This post is based on public claims made by the ransomware group "medusalocker". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.