The Medusa ransomware group published 186.36 GB of compressed data, totaling approximately 834 GB when decompressed, allegedly stolen from Comcast Corporation after the company refused to pay a $1.2 million ransom. The leaked data, made available in 47 split files on Medusa's dark web site, reportedly includes sensitive information such as Excel files with claim data specifications and Python and SQL scripts related to auto premium impact analysis. Comcast has not publicly acknowledged or responded to the breach or the data leak.
The incident follows Medusa's pattern of targeting major organizations and leaking data when ransom demands are unmet, as seen in a previous attack on NASCAR. Security researchers and Microsoft have noted that Medusa has recently exploited the critical GoAnywhere MFT vulnerability (CVE-2025-10035) to facilitate unauthenticated remote code execution in its attacks. The exposure of such a large volume of potentially sensitive data poses significant risks to Comcast and its stakeholders, underscoring the ongoing threat posed by ransomware groups leveraging high-impact vulnerabilities.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
After the ransom was not paid, Medusa posted Comcast data for download on its leak site. Reports described the exposure as 186.36 GB of compressed files, corresponding to about 834 GB of stolen data across 47 files.
The Medusa ransomware gang allegedly demanded a $1.2 million ransom from Comcast in connection with stolen company data. The later leak was reported as occurring after Comcast refused to pay.
Researchers examined a sample of data attributed to Comcast in late September 2025. The sample reportedly included Excel files on claim data specifications and Python/SQL scripts related to auto premium impact analysis.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.