MeduzaLocker claims attack on Hungry Lion network — Daily Maverick
The ransomware group MeduzaLocker has claimed an attack on the Hungry Lion fast-food restaurant chain. As Daily Maverick reports, a notice concerning the company has appeared on the darknet. According to the publication’s additional description, the group is demanding a ransom of $50,000.
Which files were published
Dark Notify, a company that analyzes cyber threats, manually reviewed the files MeduzaLocker published as evidence. Its specialists told Daily Maverick that they found no personal data in these materials that could identify customers.
According to the publication, this is not a database of personal credentials, but structured source files from point-of-sale systems. Hungry Lion has 111 outlets in South Africa, Botswana, Angola, Namibia, Zambia, Zimbabwe, Lesotho and Mauritius.
Daily Maverick also writes that MeduzaLocker is the same group responsible for the high-profile cyberattack on the logistics company The Courier Guy.
More current news is available on the UA.News Telegram channel Telegram.
Comparison with the Standard Bank leak
The publication compares the situation with the data leak at Standard Bank. According to its information, that case involved Microsoft SharePoint files containing identity document and passport numbers, active credit card numbers and driver’s licence numbers.
In Daily Maverick’s view, both cases indicate the vulnerability of unstructured and decentralized corporate systems. In the case of Hungry Lion, the publication draws attention to local logs of POS-system data imports at the chain’s branches.
Hendrik de Bruin, head of security consulting at Check Point in South Africa, said that fraud involving artificial intelligence has become a financial risk rather than merely an IT problem. He believes that the gap between formal compliance requirements and actual system resilience remains a weak point for attackers.
South Africa was removed from the Financial Action Task Force’s “grey list” on October 24, 2025, after 32 months of monitoring. At the same time, the country is undergoing an 18-month mutual evaluation scheduled to be completed in October 2027; an on-site assessment is planned for March 2027.