◇ SIGN IN
← all actors
ransomware

Money Message

dormantmedium confidence
Ransomware
Money Message
Attribution
Financially motivated (unattributed)
Origin
Unknown
First seen
2023
Last active
2024
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Egypt
Sectors
Government/taxation

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Egypt (Government/taxation sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Money Message is a double-extortion ransomware group that emerged in March 2023, best known for the MSI (Micro-Star International) breach, with limited public activity since.

History

Money Message emerged in March 2023, first reported by Zscaler ThreatLabz, conducting double-extortion attacks that encrypt data and threaten leak-site publication. Its highest-profile incident was the April 2023 breach of Taiwanese hardware maker MSI, where the group claimed roughly 1.5 TB of stolen data and a $4 million demand; the leaked data reportedly included firmware code-signing keys, raising supply-chain concern. MSI publicly confirmed a cyberattack.

The group continued claiming victims into 2024 but at a far lower tempo than major brands such as LockBit or Play, and public reporting on new Money Message activity has been sparse since, consistent with a dormant or low-activity status.

Money Message has claimed victims in Egypt among its listings. Such leak-site claims are extortion allegations and should be treated as unverified rather than confirmed breaches unless independently corroborated.

Notable campaigns

2023
MSI breach
Money Message claimed 1.5 TB stolen from MSI with a $4M demand; MSI confirmed a cyberattack and firmware signing keys were reportedly exposed.
2024
Continued low-tempo extortion
The group claimed additional victims in 2024 at a comparatively low operational tempo.
2024
Egypt leak-site listing
An Egyptian organization appeared on Money Message's leak site (claimed, not independently confirmed).

Claimed victims · 34 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
Yourway TransportationUSTransportation
Indigo EnergyUSEnergy & Utilities
Envision Unlimited
X-Copper ProfessionalUSManufacturing
ForestdaleGBProfessional Services
Family Partnerships of Central FloridaUSGovernment & Defense
Bucks County Opportunity Council, INC.USGovernment & Defense
Young Adjustment CompanyUSProfessional Services
The Tech InteractiveUSEducation
Marina Family MedicalAUHealthcare
National Atomic Energy CommissionARGovernment & Defense
KazyonRUProfessional Services