AJE Listed by medusa Ransomware Group
If you are a customer of AJE, here’s what is being claimed, and what it would mean for you.
AJE engages in the manufacture, distribution, and sale of alcoholic and nonalcoholic beverages. It was founded in 1988. AJE corporate office is located in 373 Ave Manuel Olguín Santiago De Piso 10 Surco 33, Lima, Lima Province, Peru and has 2,896 employees. The total amount of data leakage is 646,4 GB
— from Medusa’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Assessing AJE as a vendor?
Check your own domain — free, no cardEnter a work email. We count the addresses at that domain sitting in the leaked-data corpus, and how many arrived with a password.
Were you personally caught up in this? Run a free 15-second personal scan.
On June 18, 2024, Peruvian beverage company AJE appeared on the leak site operated by the Medusa ransomware group. The listing states that internal files totaling 646.4 GB were exfiltrated during a ransomware attack. Anyone whose employment, customer, supplier or partner records touched AJE’s systems may now have personal information circulating in criminal channels.
Details in the Medusa Listing
The Medusa leak site entry states that AJE, which manufactures and distributes alcoholic and nonalcoholic beverages, suffered a ransomware intrusion. It lists the data volume as 646.4 GB of internal files but does not specify the exact file types or record counts. The disclosure indicates the information was stolen and is now published for anyone to download. No ransom demand figure or negotiation status appears in the public listing. The company, founded in 1988 and headquartered in Lima, Peru, has not yet issued a public breach notification detailing what specific categories of data were taken.
Why This Matters for You and Your Family
When a company the size of AJE loses control of 646.4 GB of internal files, the exposure often includes employee payroll records, vendor contracts, customer invoices, and correspondence that contain names, addresses, national identification numbers, and financial details. If you or any member of your family has ever worked at AJE, purchased its products through a loyalty program, or supplied goods to its operations, your information could be among the stolen material. Criminal actors routinely comb these archives for identities they can impersonate, sell, or use to launch further attacks against you personally.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Doxxing and Identity-Chain Risks
A single large file dump like this one rarely stays isolated. Attackers cross-reference newly exposed names, email addresses, and phone numbers against older breaches, quickly building a complete picture of your digital life. An employee ID found in the AJE files can be paired with a password stolen from an earlier breach, giving criminals access to your email, banking, or government accounts. The same data can be sold on underground forums where doxxers publish home addresses, family member names, and photographs. Children’s gaming accounts are especially vulnerable because parents often reuse credentials across work, personal, and family entertainment logins; one leaked corporate email can lead directly to a child’s Roblox or Fortnite profile being hijacked.
Medusa’s Publicly Known Track Record
Public reporting attributes Medusa with emerging in 2021 as a ransomware-as-a-service operation that provides affiliates with encryption tools and leak-site infrastructure. The group has targeted organizations across manufacturing, healthcare, education, and logistics sectors. Its typical playbook begins with initial access gained through compromised remote desktop credentials or phishing, followed by extensive internal reconnaissance, data exfiltration, and deployment of its custom ransomware. After encryption, Medusa posts samples on its onion site and demands payment to prevent full publication. The June 18, 2024 listing of AJE fits this established pattern of dual extortion—both locking systems and threatening to release stolen files.
What to do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity so you can see exactly what the AJE files may have exposed about you.
- Rotate any password you used at AJE or any related vendor portal, then enable 2FA through an authenticator app on every account where that password was reused.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next time your information surfaces you learn within hours rather than months.
- Cover the household with DoxxScan family protection that extends to dependents and children’s gaming accounts that often chain back to the same addresses and credentials.
- Let remediation specialists handle takedown requests for any personal records that appear on data broker sites or underground marketplaces connected to this incident.
The AJE breach is a reminder that corporate ransomware incidents now function as large-scale identity exposures that can affect entire families for years. Starting with a clear map of your own exposure gives you the best chance to limit damage before criminals assemble the next link in the chain. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, and hands-on remediation by specialists, including household coverage that protects both adult accounts and children’s gaming profiles.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Skyline Implants & Periodontics Listed by Barracuda Ransomware Group
Full personal and servers files dumps from Skyline Implants & Periodontics company. The data files c…
Weber Water Resources Listed by metaencryptor Ransomware Group
Founded in 1910, Weber Water Resources has been providing the widest range of water resource solutio…
Aquamar Inc Listed by metaencryptor Ransomware Group
Aquamar, Inc. specializes in providing high-quality, wild-caught seafood products that are both deli…