Medion hack? BlackBasta ransomware has allegedly copied 1.5 TB of data

Cyber criminals claim to have successfully attacked Medion, a distributor of electronic products.

listen Print view
Stylized image with reddish conductor tracks, open lock in the foreground and the words Data Leak, Security, Exploit found

(Image: Black_Kira/Shutterstock.com)

1 min. read

Cyberattack or IT malfunction? The ransomware gang BlackBasta claims to have had access to internal data from the supplier Medion. The company has not yet confirmed this.

Medion experienced disruptions at the end of November 2024. Among other things, the website was unavailable and there were problems with emails and telephones. Internal systems and the online store are said to have been affected. The website, which is now available again, cites unspecified IT disruptions as the reason. On November 28, there was still talk of an IT incident triggered by external attackers. The answer to an inquiry from heise Security is still pending.

Screenshot from BlackBasta's leaking portal: Medion has not yet confirmed a cyberattack.

Now there is increasing evidence of a cyberattack: the criminals behind the BlackBasta blackmail Trojan claim to have successfully attacked Medion and copied 1.5 terabytes of data. This is said to include confidential business data and employee information.

Videos by heise

According to the group, the deadline is December 25. It can be assumed that they will then publish the data. Criminals usually try to blackmail companies with a leak threat. Whether there is a ransom demand and how much is currently unknown.

(des)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.