Ransomware Group medusalocker Hits: 瑞祥机电 (Ruixiang Jidian)
Summary
In the latest cybersecurity news, 瑞祥机电 (Ruixiang Jidian) — an organization based in CN — has fallen victim to a ransomware attack conducted by the group medusalocker. This data breach, discovered on 2026-09-12T09:01:44.036243+00:00, underscores the increasing need for proactive cybersecurity defenses as we continue through 2026.
Incident Report
| Attribute | Information |
|---|---|
| Target Organization | 瑞祥机电 (Ruixiang Jidian) |
| Threat Group | medusalocker |
| Summary | Elevator manufacturer, brand 银海 (Yinhai). Produces machine-room-less (MRL) passenger elevators and OEMs elevator components (car top/bottom, car wall panels, COP, doors) for OTIS, KONE, Hitachi, Toshiba, TKS (蒂升). Export business (project DUBROVSKIY-2, customer 赛博). Infrastructure: Synology NAS (admin), IT dept with Epson L1118. | China, Jiangsu Province (黎民北路 / Limin North Road) |
| Date of Breach | 2026-09-12T09:01:31.202699+00:00 |
| Discovery Date | 2026-09-12T09:01:44.036243+00:00 |
| Region | CN |
| Business Sector | Manufacturing |
How to reduce your ransomware risk
Most ransomware intrusions start with a stolen password or a phishing email. A few proactive steps sharply cut your exposure:
- dark web monitoring — close the gap attackers exploit.
- data breach monitoring — close the gap attackers exploit.
Want to know if you’re already exposed? Run a free scan with the HookPhish data breach checker.
Disclaimer
HookPhish does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.
