Skip to main content
Back to overview
High

Prestige Maintenance Suffers Data Breach, Medusa Ransomware Claims Responsibility, Affecting 65,452 Individuals

American cleaning firm Prestige Maintenance hit by major data breach American commercial cleaning company Prestige Maintenance said it suffered a significant data security incident earlier this year that compromised the…

Key points

  • Unusual activity detected on or about January 17, 2025.
  • Unauthorized access to files confirmed.
  • Medusa ransomware group claimed responsibility.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Jan 17, 2025
Updated
Jul 22, 2026
Confidence
High
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch phishing, executive impersonation and account-takeover exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

PrestigemaintenanceData DisclosureMedusa Ransomware Claims ResponsibilityAffectingIndividuals AmericanPrestige MaintenanceAmericanHeadquarteredPlanoTexas

Quick context

Questions about this signal

What happened in this signal?

American cleaning firm Prestige Maintenance hit by major data breach American commercial cleaning company Prestige Maintenance said it suffered a significant data security incident earlier this year that compromised the sensitive personal data of more than 65,000 individuals. Headquartered in Plano, Texas, Prestige Maintenance provides scalable janitorial and facilities maintenance services across Chicago, Dallas, Kansas City, and St. Louis. In a data security incident notice filed with the Office of Maine Attorney General, Prestige Maintenance said that on May 13, it identified a data security incident. The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident. The company also took steps to contain the incident, secure the affected network and notified relevant law enforcement authorities about the same. “We learned of unusual activity in a segment of our cyber environment on January 17, 2025, and immediately started an investigation, engaging independent experts to assist. We later learned that some of our files had been accessed without authorisation,” Prestige Maintenance said. The compromised data included names and other personal information including Social Security Numbers. The filing with the Maine state regulator also states that the company has identified at least 65,452 individuals impacted by the incident. Prestige Maintenance has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general. It has also offered one year of complimentary identity protection and credit monitoring services through IDX to all affected individuals. 🚨 Medusa Ransomware Alert 🚨 Prestige Maintenance USA 🇺🇸 Prestige Maintenance USA, a national facilities maintenance company based in Texas falls victim to Medusa Ransomware. Group claims to have obtained organization's data. Note: Prestige Maintenance USA had previously… pic.twitter.com/kad0IJ9okc While Prestige Maintenance did not disclose details of the security incident, the Medusa ransomware group claimed responsibility for the cyber attack and listed the organisation as a victim on its data leak site. The group said it had stolen confidential data from the cleaning company and gave it 8 days to pay a ransom of $1.2 million. Prestige Maintenance did not comment on Medusa’s claims or its decision regarding the ransom payment. "AI-led spear phishing worries me the most" - Darktrace's Dave Palmer "Crisis or no crisis; security needs to be the same" "People need to understand that there isn't an invisible force-field that's protecting them" "The community needs to recognise and understand crime" "We've seen a marked increase in social engineering attacks" $12M Vanishes in Crypto Heist Targeting Cork Protocol’s Depeg Market $600 million stolen & returned in biggest ever crypto heist '+comparitech_frontend_data.translations["comments-submitted-published-after-approval"]+"

When was this signal reported?

Shadow Tier lists Jan 17, 2025 as the signal date.

Which organization is connected to this signal?

Prestigemaintenance is the organization connected to this public signal.

Explore Prestigemaintenance
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence