Medusa threat actors have claimed responsibility for a ransomware attack targeting Atrium Living Centers, a healthcare provider dedicated to high-quality long-term and rehabilitative care across several U.S. states. The attack has impacted the organization’s operations in the United States. #UnitedStates
Incident Details
- Victim: Atrium Living Centers
- Country: US
- Actor: medusa
- Source: http://xfv4jzckytb4g3ckwemcny3ihv4i5p4lqzdpi624cxisu35my5fwi5qd.onion/detail?id=67741bb987a8e3e4ab91543894e76f86
- Discovered: 2025-11-09 18:42:58.778387
- Published: 2025-11-08 15:21:05.000000
Information
- The organization is dedicated to delivering compassionate, high-quality healthcare to residents while promoting dignity, respect, and community involvement.
- Offers both short-term post-acute rehabilitation and long-term nursing care with a focus on personalized treatment.
- Operates multiple care centers across Ohio, Michigan, Kentucky, and Wisconsin.
- Headquartered at 2550 Corporate Exchange Drive, Suite 200, Columbus, Ohio 43231, United States.
- Employs approximately 2,000 staff members.

Disclaimer: This post is based on public claims made by the ransomware group "medusa". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.