NASCAR (National Association for Stock Car Auto Racing) has confirmed a significant data breach after discovering unauthorized access to its network following a cyberattack in late March 2025. The incident, detected on April 3, exposed the names and Social Security numbers of an unknown number of individuals. Details emerged via official filings with state regulators in Maine, New Hampshire, and Massachusetts, but the exact scope remains undisclosed[1][3][8].
The Medusa ransomware group claimed responsibility, adding NASCAR to their dark web leak site and demanding a $4 million ransom by April 19, 2025. Medusa published samples of allegedly stolen data to pressure the organization, including internal maps, personnel info, and business documents. It’s unclear if NASCAR paid or if the data was published in full[3][5][6][8][17].
Medusa is one of the most prolific ransomware actors in 2025, using “double extortion” (encrypting files and threatening to leak stolen data). The FBI and CISA have linked Medusa to 300+ attacks this year—including high-profile incidents in healthcare, education, finance, and government sectors worldwide[7][10][13][18][20]. Notable Medusa breaches include the Minneapolis Public Schools and several major enterprises.
If you received a notification from NASCAR, enroll in credit monitoring and review your accounts for suspicious activity.
Written by
Research
A DevOps engineer and cybersecurity enthusiast with a passion for uncovering the latest in zero-day exploits, automation, and emerging tech. I write to share real-world insights from the trenches of IT and security, aiming to make complex topics more accessible and actionable. Whether I’m building tools, tracking threat actors, or experimenting with AI workflows, I’m always exploring new ways to stay one step ahead in today’s fast-moving digital landscape.
Get the latest cybersecurity insights delivered to your inbox.