RANSOMWARE VICTIMFINANCIAL SERVICESDUPLICATE CLAIM

Simon Property Group

medusa📍 United States (US)📅 October 28, 2025
8
same group

Attack Intelligence

Simon Property Group was compromised in a ransomware attack attributed to medusa in October 2025. The organization, operating in the Financial Services sector in United States, was added to the group's data leak site as part of an extortion campaign.

medusa operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.

Simon Property Group is a leading real estate investment trust (REIT) based in Indianapolis, Indiana. Founded in 1993, it owns, develops, and manages premier shopping malls, outlets, and lifestyle centers across the United States and internationally. The company’s well-known properties include Premium Outlets and The Mills centers. Led by CEO David E. Simon, it focuses on creating high-quality retail and entertainment destinations that attract millions of visitors each year. Despite challenges from online retail, Simon Property Group continues to innovate by combining shopping, dining, and mixed-use spaces, maintaining its position as a global leader in retail real estate. company is headquartered in 225 West Washington Street, Indianapolis, Indiana 46204, USA. 3,000 employees

Additional Details

ransom
1200000

Other Victims — medusa (8)

Quick Facts

CountryUnited States (US)
SectorFinancial Services
Attack DateOct 28, 2025
Intel Sourceransomware.live
StatusDUPLICATE CLAIM

Threat Group

medusa
Motivation: financial
View group profile →

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.