RANSOMWARE VICTIMCONSUMER SERVICESDUPLICATE CLAIM

Balloons Everywhere

medusa📍 United States (US)📅 January 29, 2026
8
same group

Attack Intelligence

Balloons Everywhere was compromised in a ransomware attack attributed to medusa in January 2026. The organization, operating in the Consumer Services sector in United States, was added to the group's data leak site as part of an extortion campaign.

medusa operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Balloons.com is a wholesale distributor specializing in a wide range of balloon products including foil film, latex balloons, and balloon decoration kits. They cater to various themes, occasions, and licensed characters, offering items for both everyday events and special celebrations. Their services target individuals and businesses looking for party supplies, with a focus on DIY balloon decor and promotional products. Additionally, they provide customers with resources and learning tools related to balloon usage and care. The company headquarters is located in 16474 Greeno Road, Fairhope, AL 36532-5528, United States. 11-50 Employees

Additional Details

ransom
150000

Other Victims — medusa (8)

Quick Facts

CountryUnited States (US)
SectorConsumer Services
Attack DateJan 29, 2026
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

medusa
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.