The Medusa ransomware group publicly claimed responsibility for a significant cyberattack against Comcast Corporation, one of the world's largest media and technology companies. According to statements posted on Medusa's dark web leak site, the attackers exfiltrated approximately 834.4 gigabytes of internal data from Comcast. The group demanded a ransom of $1.2 million, offering the data for sale to interested buyers or, alternatively, to Comcast itself for deletion. To substantiate their claims, Medusa published around 20 screenshots allegedly depicting internal Comcast files, as well as a comprehensive file listing containing 167,121 entries. The exposed files reportedly include actuarial reports, product management data, insurance modeling scripts, claim analytics, and various Python and SQL scripts related to auto premium impact analysis. The attack was first publicized on September 26, 2025, and further detailed on September 28, 2025, through Medusa's leak site. While Comcast has not officially confirmed the breach, the scale and specificity of the data samples have raised significant concerns within the cybersecurity community. Medusa is known for its double extortion tactics, combining data encryption with exfiltration and public shaming to pressure victims. The group has a history of targeting large organizations and auctioning stolen data to third parties, increasing the risk of exposure for affected entities. The potential operational, regulatory, and reputational impacts for Comcast are substantial, particularly if sensitive partner or customer data is included in the breach. Industry observers note that this incident underscores the evolving threat landscape of ransomware in 2025, where attackers leverage both technical and psychological pressure. The breach has prompted renewed calls for rigorous defense-in-depth strategies and mature incident response protocols among large enterprises. Data protection regulations may subject Comcast to heightened scrutiny if the breach is verified and sensitive information is confirmed. The incident also highlights the importance of monitoring dark web leak sites and threat intelligence sources for early detection of such claims. Medusa's approach in this case mirrors its broader campaign of aggressive extortion and public exposure. The attack serves as a stark reminder of the persistent and adaptive nature of ransomware threats facing critical infrastructure and major corporations. Security teams are advised to review their incident response and data protection measures in light of this high-profile breach. The full extent of the data compromised and the potential downstream effects remain under investigation. The Medusa-Comcast incident is likely to influence both industry best practices and regulatory expectations in the near future.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Multiple reports said the Medusa ransomware group listed Comcast as a victim and claimed to have stolen a large volume of company data. The gang reportedly demanded a $1.2 million payment in connection with the alleged breach.
3 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcescworld.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.