Incident analysis
瑞祥机电 (Ruixiang Jidian) was listed by Medusalocker ransomware, a group with 77 victims recorded in this database. The listing appeared on the group's leak site on September 12, 2026.
瑞祥机电 (Ruixiang Jidian) is based in China and operates in the Manufacturing sector. China ranks #28 worldwide for ransomware disclosures, with 123 victims in this database.
Sector context. Manufacturing companies are frequently targeted because production downtime directly translates to financial loss. Ransomware operators exploit this time-sensitivity to demand higher ransoms and faster payment.
Medusalocker typically follows a double extortion model: data is exfiltrated from the victim's systems before files are encrypted, so the victim faces two demands at once — pay to restore access, and pay to keep stolen data unpublished. The leak site, where this listing appeared, is the lever for the second demand.