2024 Compass Group (Australia foodservice) — Medusa ransomware; employee HR artifact exposure
Data compromised
Employee HR and identity verification documents per corporate incident page and press summaries
Technical writeup
Compass Group's Australian operating company confirmed early-September 2024 criminal activity after Medusa extortionists claimed nearly a terabyte of exfiltrated personnel records—passports, licenses, and wage paperwork—aligned with Compass Group plc's global contract-foodservice brand. The vendor stood up public cyber-support guidance acknowledging localized data theft while restoration and identity-support workflows progressed.
Root cause
Ransomware and data-extortion operation attributed in CyberDaily and specialty reporting to the Medusa collective