On September 30, 2024, the Medusa ransomware group added Sub-Zero, Wolf, and Cove to its public leak site, claiming that the Wisconsin-based luxury kitchen appliance manufacturer had been hit by a ransomware attack in which attackers exfiltrated 760.60 GB of internal files.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Sub-Zero
Get alerted the next time Sub-Zero files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Sub-Zero’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Medusa Listing
The primary disclosure on the Medusa leak site states that internal files were exfiltrated during a ransomware attack against the company. The listing does not specify the exact types of data taken, nor does it quantify how many individuals may be affected. It simply lists Sub-Zero, Wolf, and Cove alongside the volume of data obtained and gives the company a deadline to negotiate before the files are fully published. Public reporting on Medusa indicates the group follows a double-extortion model: encrypting systems where possible while threatening to release stolen data if ransom demands are not met.
Why This Matters for You and Your Family
Sub-Zero, Wolf, and Cove customers, service technicians, suppliers, and employees may have personal information stored in the compromised internal files. Even though the exact data types remain unknown, corporate records of this size routinely contain names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, payment details, and employee records. If your information is among the 760.60 GB now in criminal hands, it can be used for identity theft, tax fraud, or targeted phishing. Your family is exposed the moment any single member’s details surface in follow-on sales on dark-web markets.
Doxxing and Identity-Chain Risks
A breach of this scale rarely stops at one company. Attackers and data resellers combine corporate leaks with other exposures to build complete identity chains. An email address allegedly taken from Sub-Zero, Wolf, and Cove internal files can be cross-referenced with credential leaks, shopping accounts, and children’s gaming profiles that share the same household address or parent email. This linkage turns a single breach into persistent doxxing material—home addresses, phone numbers, and family relationships become easy to trace. Credential leaks like this one frequently cascade into account takeovers on gaming platforms, where children’s usernames and passwords are reused across services.