RANSOMWARE VICTIMENERGYDUPLICATE CLAIM

EcoPetróleo

medusa📍 Brazil (BR)📅 October 12, 2025
8
same group

Attack Intelligence

EcoPetróleo was compromised in a ransomware attack attributed to medusa in October 2025. The organization, operating in the Energy sector in Brazil, was added to the group's data leak site as part of an extortion campaign.

medusa operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

EcoPetróleo is dedicated to providing petroleum products while actively engaging in environmental conservation initiatives in the Dominican Republic. The company emphasizes its commitment to corporate social responsibility through projects such as turtle nesting, beach clean-ups, and recycling programs. Their intended clients include individuals and organizations that value sustainable practices and eco-friendly services. With a focus on community and environmental welfare, EcoPetróleo strives to enhance the quality of life for all. company is headquartered in Avenida Rómulo Betancourt No. 527, El Renacimiento, Santo Domingo, Distrito Nacional, República Dominicana. 379 Employees

Additional Details

ransom
100000

Other Victims — medusa (8)

Quick Facts

CountryBrazil (BR)
SectorEnergy
Attack DateOct 12, 2025
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

medusa
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.