RANSOMWARE VICTIMHEALTHCAREDUPLICATE CLAIM

JBS

medusa📍 United States (US)📅 December 23, 2025
8
same group

Attack Intelligence

JBS was compromised in a ransomware attack attributed to medusa in December 2025. The organization, operating in the Healthcare sector in United States, was added to the group's data leak site as part of an extortion campaign.

medusa operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

JBS is a regional, public, nonprofit corporation established under Act 310 of the 1967 Alabama Legislature. The region served by the Authority is designated in the State Mental Health Plan as Region M-5, and comprises Jefferson, Blount and St. Clair counties, with a total of more than 800,000 residents. There are three mental health centers which serve the region. It is the responsibility of the Authority to plan, coordinate and develop the system of mental health services for the entire region. The Authority provides consultation regarding program development and funding; coordination of regional programs; delivery of region-wide services; and a consolidated budgeting process to simplify the funding of programs at the local and state level. company is headquartered in 940 Montclair Rd., Birmingham, AL 35213, USA. 201-500 Employees, The total amount of data leakage is 168.6 GB.

Additional Details

ransom
200000

Other Victims — medusa (8)

Quick Facts

CountryUnited States (US)
SectorHealthcare
Attack DateDec 23, 2025
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

medusa
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.