teiss – News – Hungry Lion fast food chain hit by ransomware attack claimed by MeduzaLocker | #ransomware | #cybercrime


A ransomware group known as MeduzaLocker has claimed responsibility for a cyberattack on Hungry Lion, a quick-service restaurant chain operating 111 locations across South Africa, Botswana, Angola, Namibia, Zambia, Zimbabwe, Lesotho and Mauritius.

 

The breach was identified on Aug. 27, 2026, at 06:27 UTC through a dark web threat intelligence sweep, and the same group has been linked to a prior attack on logistics provider The Courier Guy.

The listing surfaced as part of a broader pattern of cyberattacks affecting organizations in South Africa. Threat intelligence firm Dark Notify reviewed the data posted as evidence and said that no personally identifiable information appeared to be compromised. Rather than a cache of personal credentials, the exposed files consist of structural outputs from Hungry Lion’s point-of-sale systems, which include Unity POS, generating roughly 242 megabytes of data monthly; GAAP POS, updated daily; and CoSoft POS, spanning 145 terminals.

The incident follows a separate breach at Standard Bank, which its chief information officer, Jorg Fischer, characterized as limited to Microsoft SharePoint data. That breach, however, involved a cache of identification and passport numbers, active credit card numbers and driver’s licenses. Together, the two incidents point to weaknesses in unstructured and decentralized corporate systems: Standard Bank’s exposure originated in unstructured files such as spreadsheets and PDFs, while Hungry Lion’s stemmed from localized, branch-level point-of-sale import logs.

The timing has drawn added scrutiny because of South Africa’s ongoing anti-financial-crime monitoring. The country was removed from the Financial Action Task Force’s gray list on Oct. 24, 2025, following a 32-month monitoring period, but remains subject to an 18-month mutual evaluation process set to conclude in October 2027, with a critical on-site assessment scheduled for March 2027. A pattern of unresolved corporate and public data breaches, including those at Standard Bank, Liberty and Hungry Lion, could jeopardize that standing, since the Financial Action Task Force, working with Interpol and the Egmont Group, has identified proceeds from cyber-enabled fraud as among the fastest-growing forms of illicit financial flow worldwide.



Click Here For The Original Source.

——————————————————–

..........

.

.