RANSOMWARE VICTIMEDUCATIONDUPLICATE CLAIM

Universidade Municipal de São Caetano

medusa📍 Brazil (BR)📅 November 24, 2025
8
same group

Attack Intelligence

Universidade Municipal de São Caetano was compromised in a ransomware attack attributed to medusa in November 2025. The organization, operating in the Education sector in Brazil, was added to the group's data leak site as part of an extortion campaign.

medusa operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

USCS offers a diverse range of educational programs including in-person and distance learning undergraduate degrees, technical courses, and postgraduate studies such as MBAs and doctorates. The university also provides non-degree courses aimed at skill enhancement and is equipped with facilities for secondary education. Services include free legal assistance, fiscal education, and health services, catering to both students and the community. With a focus on quality and flexibility, USCS serves a wide array of clients including students at various academic levels and professionals seeking further education. company is headquartered in Rua Santo Antônio, 50 – Centro, São Caetano do Sul, SP, CEP 09521-160. 501-1,000 Employees,

Additional Details

ransom
250000

Other Victims — medusa (8)

Quick Facts

CountryBrazil (BR)
SectorEducation
Attack DateNov 24, 2025
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

medusa
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.