← Hungry Lion

2026 Hungry Lion — MedusaLocker leak-site claim; POS logs, no PII in samples (unverified)

2026 Unknown records affected Share on X

Data compromised

Actor-listed branch POS import logs per threat-intel review; ~$50k ransom demand cited — customer credentials/PII not observed in published samples (unverified)

Technical writeup

Unverified ransomware/extortion claim — August 27, 2026. Daily Maverick reported MedusaLocker listed Hungry Lion, a southern African quick-service restaurant chain (~111 locations), with a cited $50,000 ransom demand; the same actor group was linked to The Courier Guy logistics attack. Threat-intelligence firm Dark Notify reviewed actor “evidence” files and told the outlet the sample appeared to be Point-of-Sale system structural outputs rather than a customer PII database. Hungry Lion had not publicly confirmed at indexing. recordsAffected 0 — no attested person census; companyConfirmed false.

Root cause

Unverified MedusaLocker listing vs Hungry Lion (111-location QSR chain); Dark Notify analysis of actor samples found POS structural outputs, not customer PII (Daily Maverick Aug 27)

References