The Medusa ransomware gang is claiming responsibility for an alleged NASCAR data breach that allegedly leaked one terabyte (1,038.70 GB) of data.
Daytona Beach, Florida-based National Association for Stock Car Auto Racing (NASCAR) manages over 1,500 races annually across different countries, making it one of the most prominent sports associations.
On April 8, 2025, Medusa listed NASCAR on its data leak site and demanded $4 million in ransom to avoid publishing the stolen data that it says includes sensitive internal documents. NASCAR has until April 19 to pay up, but can extend the deadline for $100,000 per day.
NASCAR data breach allegedly leaks sensitive files
The data breach allegedly leaked employee names, email addresses, phone numbers, sponsorship agreements, invoices, detailed racetrack maps, and even legal documents. Documents published on Medusa’s data leak site as proof of the alleged data breach include corporate branding materials, employee details, racetrack maps, and internal notes.
However, NASCAR has neither confirmed nor denied the data breach, casting a shadow of uncertainty, especially amid upcoming partnerships and sports events.
Straight out of the cybercriminals’ playbook, ransomware gangs frequently target companies during financially significant moments to gain leverage and force them into paying the ransom to avoid bad publicity.
Nonetheless, NASCAR has not confirmed being contacted by the cyber gang to discuss ransom payment. However, being listed on a data leak site significantly reduces the chances of a ransom payment, since the data breach becomes public knowledge. Paying also does not guarantee that the cybercriminals will not sell or misuse the stolen data.
Meanwhile, NASCAR has not disclosed if the alleged data breach stemmed from a ransomware attack or was a pure exfiltration incident. As a ransomware-as-a-service (RaaS) operator, Medusa thrives on double extortion involving encrypting devices and threatening to leak the stolen information if the victim refuses to pay.
Medusa ransomware impacted over 300 organizations since 2021
Since emerging in 2021, the ransomware gang has victimized over 300 organizations, including critical infrastructure organizations, such as healthcare and educational institutions, manufacturing, and technology companies, prompting the FBI, CISA, and MS-ISAC to issue a joint cybersecurity advisory.
In light of the ongoing Medusa attacks, the agencies urged critical infrastructure entities to implement multi-factor authentication to thwart the gang’s encryption attempts.
Besides NASCAR, the Medusa ransomware gang claims to have recently breached McFarland Commercial Insurance Services, Bridgebank Ltd, and Pulse Urgent Care.
In 2023, the ransomware gang also breached the Minneapolis Public Schools district and leaked sensitive student and employee data after its ransom demands were ignored. Heartland Health Center, Bell Ambulance in Wisconsin, Customer Management Systems, and CPI Books have also suffered Medusa ransomware attacks.
This is also hardly the first time NASCAR has suffered a data breach. In 2016, a NASCAR team suffered a TeslaCrypt ransomware attack that encrypted and leaked files. NASCAR’s X account was also seemingly hacked and used to advertise a new cryptocurrency token, just as the NBA’s.
Undoubtedly, sports associations are lucrative targets for cyber attacks due to the vast amounts of operational and personal information they collect. Their popularity and strong financial position also make them prime targets for high-profile cybercrime gangs, such as Medusa, looking for huge payouts.

