Twal Family IT Labβs personal home lab in the twalfamily.com AD environment was impacted by the medusalocker ransomware, disrupting operations across VMware vSphere and multiple Active Directory domains. No evidence indicates a corporate/enterprise target, but prior reporting mistakenly referenced forces/forces.gc.ca, with the victim tied to Canada. #Canada
Incident Details
- Victim: Twal Family IT Lab
- Sector: Technology
- Country:
- Actor: medusalocker
- Source: http://t33zoj4qwv455fog7qnb2azi5xcdxkixughmmduzbw2rtdgryqfbh6id.onion/company/banajah-bajapah/
- Discovered: 2026-08-16T15:21:57.640362+00:00
- Published: 2026-08-16T15:21:45.319791+00:00
Information
- Twal Family IT Lab was identified as the ransomware victim.
- The incident involved the MedusaLocker actor.
- The target was a personal IT home lab rather than a corporate environment.
- The environment included an AD domain: twalfamily.com.
- The setup also used VMware vSphere and multiple AD domains.
- Daniel Al Twal works at Technology North Corp in Edmonton and is a former DND co-op.
- It was previously misidentified as Forces/forces.gc.ca.
- The associated address is 4172 Wolfe Point Way, Ottawa, ON K1V 1P5, Canada.

Disclaimer: This post is based on public claims made by the ransomware group "medusalocker". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.