On June 18, 2024, Peruvian beverage company AJE appeared on the leak site operated by the Medusa ransomware group. The listing states that internal files totaling 646.4 GB were exfiltrated during a ransomware attack. Anyone whose employment, customer, supplier or partner records touched AJE’s systems may now have personal information circulating in criminal channels.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch AJE
Get alerted the next time AJE files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about AJE’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details in the Medusa Listing
The Medusa leak site entry states that AJE, which manufactures and distributes alcoholic and nonalcoholic beverages, suffered a ransomware intrusion. It lists the data volume as 646.4 GB of internal files but does not specify the exact file types or record counts. The disclosure indicates the information was stolen and is now published for anyone to download. No ransom demand figure or negotiation status appears in the public listing. The company, founded in 1988 and headquartered in Lima, Peru, has not yet issued a public breach notification detailing what specific categories of data were taken.
Why This Matters for You and Your Family
When a company the size of AJE loses control of 646.4 GB of internal files, the exposure often includes employee payroll records, vendor contracts, customer invoices, and correspondence that contain names, addresses, national identification numbers, and financial details. If you or any member of your family has ever worked at AJE, purchased its products through a loyalty program, or supplied goods to its operations, your information could be among the stolen material. Criminal actors routinely comb these archives for identities they can impersonate, sell, or use to launch further attacks against you personally.
Doxxing and Identity-Chain Risks
A single large file dump like this one rarely stays isolated. Attackers cross-reference newly exposed names, email addresses, and phone numbers against older breaches, quickly building a complete picture of your digital life. An employee ID found in the AJE files can be paired with a password stolen from an earlier breach, giving criminals access to your email, banking, or government accounts. The same data can be sold on underground forums where doxxers publish home addresses, family member names, and photographs. Children’s gaming accounts are especially vulnerable because parents often reuse credentials across work, personal, and family entertainment logins; one leaked corporate email can lead directly to a child’s Roblox or Fortnite profile being hijacked.