A major Australian state government department has denied claims made a ransomware actor after being listed on its darknet leak site last week.
Medusalocker listed NSW Health in a post dated August 27, claiming to have “extracted” 103 emails from the department.
The threat actor shared a limited file tree of documents allegedly stolen from NSW Health in folders with names such as HR, Clients, Reports, and Marketing. The documents therein appear to be legitimate; however, the letterhead on each is from a different medical or dental practice from across New South Wales, particularly from the North Coast and Hunter regions.
For its part, NSW Health said it cannot find any evidence its systems have been impacted.
“NSW Health has rigorous cyber security measures in place to protect NSW Health’s core network, applications and data,” a department spokesperson told Cyber Daily.
“There is currently no evidence of any cyber security event affecting NSW Health systems or data.
“NSW Health continues to work closely with Cyber Security NSW and federal cyber security departments to monitor and protect its systems.
“NSW Health also continues to work with staff and vendors to provide education and training initiatives focused on cyber security measures.”
Given that NSW Health does not appear to be the victim, and yet patient data dating from at least 1999 to 2026 appears to be impacted, it may be the case that the data was exfiltrated from a third-party service provider. The data includes patient medical scans, Medicare numbers, and personal information such as addresses and contact information.
Cyber Daily has so far been unable to determine if that is the case, nor ascertain the identity of that potential third party.
Who is MedusaLocker?
First observed in 2021, MedusaLocker is one of the less active groups operating in the ransomware space, with less than 100 victims to its name.
The group had been relatively inactive for several months, with activity only really restarting in May 2026, when it posted the details of 15 victims throughout the course of the month. It was quiet again in June, with activity ramping up again in July and August.
When the group is active, MedusaLocker mainly targets entities in the United States and Germany, with Australia ranking seventh with two victims, the other being hospitality giant the Oscars Group, which was listed by the hackers in a November 2025 leak post.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.