On December 13, 2025, Indonesian palm oil producer PT Sampoerna Agro Tbk appeared on the Medusa ransomware group’s leak site, with the attackers claiming to have exfiltrated internal company files.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details of the Incident
Public reporting indicates the company, founded in 1993 and headquartered in South Sumatra with its main office in Jakarta, was listed after a ransomware deployment. The exposed material consists of internal files rather than a clearly catalogued customer database. No exact number of affected individuals has been confirmed, though the company employs between 5,000 and 10,000 people. Available reporting describes the data as business records that could contain employee or partner information. The listing carries a typical extortion deadline common to Medusa posts, though the precise date has not been independently verified in open sources.
Why This Matters for You and Your Family
When a company that employs thousands of ordinary workers suffers a breach, the ripple effects reach far beyond the corporate walls. If your employer, your spouse’s employer, or a supplier you deal with is involved, personal details such as work emails, phone numbers, addresses, or payroll records may now sit on a dark-web leak site. That information can be combined with other leaks to build a profile that puts your household at risk of identity theft, phishing campaigns, or physical harassment. Children’s school records, family medical details, or spouse’s employment data sometimes travel in the same datasets, turning one corporate incident into a family exposure.
The Doxxing and Identity-Chain Risks
Ransomware operators rarely stop at dumping random files. Once internal documents leave the victim’s network, they often surface in forums where opportunistic criminals search for names, employee IDs, and contact details. These fragments link to your personal accounts across social media, shopping sites, and gaming platforms. A single work email from the Sampoerna Agro files can become the starting point for credential-stuffing attacks that compromise your bank login, streaming services, or children’s gaming accounts. The chain reaction is fast: one exposed record today can unlock doxxing packages sold tomorrow that include home addresses, family member names, and phone numbers.