Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Medusa Group

Medusa Group Vendor Cyber Rating & Cyber Score

medusagroup.pl

Medusa Group Architects Medusa Group is an interdisciplinary design studio established in 1997 in Silesia by Przemo Łukasik and Łukasz Zagała. Over the past twenty years, the team of its young architects has significantly expanded their scope of activity gaining specialised experience and becoming one of the most recognisable project brands in Poland and abroad. Practice is located in two cities in Poland: Warsaw and Bytom and is active as Medusa London Limited in London. Medusa Group has won over 20 competitions and has been awarded over 30 prizes, as well as three nominations to the prestigious Miesa van der Rohe award. The office is involved in urban and architectural projects in different scales. From master plans for new or


Medusa Group A.I CyberSecurity Scoring

Medusa Group
Company Information
Website:http://www.medusagroup.pl
Employees number:57
Number of followers:0
NAICS:54131
Industry Type:Architecture and Planning
Homepage:medusagroup.pl
Medusa Group Risk Score (AI oriented)
Between 700 and 749
logo
Medusa GroupArchitecture and Planning
Updated:
11/06/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Medusa Group Global Score (TPRM)
xxxx
logo
Medusa GroupArchitecture and Planning
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Medusa Group
Medusa GroupModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
-68 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
751Before Incident
JUNE 2026
749Before Incident
MAY 2026
749Before Incident
APRIL 2026
814Before Incident
Ransomware
01 Apr 2026Medusa Group
The Gentlemen, Medusa and Cisco: The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

The Gentlemen Ransomware Operation: A Rising Threat with AI and RaaS Roots

746After Incident
CRITICAL-68
MEDCISOPE1781209579
The Gentlemen Ransomware Operation: A Rising Threat with AI and RaaS Roots A new analysis by PRODAFT has uncovered the evolution of The Gentlemen, a financially motivated ransomware group that began as an affiliate for established ransomware-as-a-service (RaaS) operations like LockBit, Qilin, and Medusa before launching its own independent program in July 2025. Tracked as Phantom Mantis, the group is led by a Russian-speaking cybercriminal known as LARVA-368 a 36-year-old identified as Alexander Andreevich Yapaev from Izhevsk, Russia, with aliases including hastalamuerte, ArmCorp, and santamuerte. Since its inception, The Gentlemen has claimed 478 victims, with a surge in activity making it one of the most prolific ransomware actors, responsible for 10% of global ransomware incidents in April 2026. The group’s transition to independence followed a payment dispute with Qilin, where LARVA-368 accused the RaaS operator of an exit scam, allegedly defrauding affiliates of $48,000. PRODAFT noted that Phantom Mantis may have spread disinformation to recruit Qilin affiliates by discrediting the group. The Gentlemen operates with a sophisticated infrastructure, leveraging AI for ransomware development, tool maintenance, and post-exploitation procedures. Its affiliate program offers a 90/10 profit split, attracting partners with aggressive incentives. Affiliates must provide at least 1GB of stolen victim data to access the panel, a tactic designed to block researchers and law enforcement. The group supports multiple ransomware variants, including Windows, Linux, ESXi, and LVM-targeting strains, and uses open-source messaging platforms like Tox and SimpleX Chat for communication. Initial access is typically gained through vulnerable edge devices particularly Cisco and Fortinet FortiGate systems followed by Active Directory exploitation using tools like NetExec, RelayKing, and PrivHound. The ransomware employs a hybrid encryption scheme (X25519 key exchange with XChaCha20) and can self-propagate as a worm when executed with the `--spread` argument. Microsoft, tracking the group as Storm-2697, noted that the Go-based malware is obfuscated with Garble and can wipe recoverable artifacts when run with the `--wipe` flag. The Gentlemen’s attacks exhibit a high degree of adaptability, with dwell times ranging from two to six weeks. The group targets VMware infrastructure and employs multi-channel extortion, combining ransomware with email and phone-based pressure tactics. A recent leak of the group’s internal Rocket.Chat database spanning November 2025 to April 2026 revealed a structured criminal enterprise with clear role divisions, exploiting vulnerabilities like CVE-2024-55591, CVE-2025-32433, and CVE-2025-33073. In March 2026, an exposed toolkit on a Russian bulletproof host further exposed the group’s full intrusion lifecycle, from reconnaissance to encryption. Victim distribution is global, with only 13% in the U.S., while the majority are concentrated in Thailand, the U.K., Brazil, Germany, and India. The group’s rapid development cycle was demonstrated in April 2026 when it released a same-day patch after a decryptor was made public. With roots dating back to at least 2020 including prior affiliations with the Embargo ransomware group LARVA-368’s expertise has positioned The Gentlemen as a formidable and evolving threat in the cybercrime landscape.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: 1GB+ of stolen victim data (minimum requirement for affiliates)WindowsLinuxESXiLVMOperational Impact: Multi-channel extortion (ransomware, email, phone-based pressure tactics)
DATA BREACH
Type Of Data Compromised: Stolen victim data (including sensitive corporate information)Sensitivity Of Data: High (used for extortion)
MARCH 2026
814Before Incident
FEBRUARY 2026
814Before Incident
JANUARY 2026
814Before Incident
DECEMBER 2025
814Before Incident
NOVEMBER 2025
814Before Incident
OCTOBER 2025
814Before Incident
SEPTEMBER 2025
814Before Incident
AUGUST 2025
814Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Medusa Group ?
?
What was Medusa Group's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Medusa Group's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Medusa Group's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Medusa Group's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Medusa Group's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Medusa Group's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Medusa Group's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Medusa Group's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Medusa Group's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Medusa Group's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Medusa Group's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on Medusa Group's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Medusa Group ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Medusa Group's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Medusa Group Cyber Scoring History | Rankiteo