On November 5, 2025, LaRosa’s Pizzeria appeared on the leak site of the Medusa ransomware group, with the attackers claiming to have exfiltrated internal company files following a ransomware incident at the family-owned Ohio-based restaurant chain.
Watch LaRosa’s Pizzeria
Get alerted the next time LaRosa’s Pizzeria files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about LaRosa’s Pizzeria’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Medusa posted details of the LaRosa’s breach on its dark web leak portal. The company, founded in 1954 in Cincinnati, operates dozens of locations across Ohio, Kentucky, and Indiana. Available reporting describes the exposed material as internal files, though the precise volume and specific data types have not been independently verified by third parties. No confirmed customer count or exact list of exposed record types has been published. The Medusa leak site entry carries the identifier that links it directly to this incident.
Why This Matters for You and Your Family
When a local business like LaRosa’s suffers a breach, the information it holds on customers, employees, suppliers, and partners can end up in the hands of criminals. Internal files often contain names, addresses, phone numbers, email accounts, order histories, payment details, or employee records. Once that data leaves the company’s control, it can be sold, traded, or used to target you directly. For families who have ordered takeout, joined loyalty programs, or had their information collected during catering events, the breach creates a fresh exposure that may not show up in older breach databases for weeks or months.
The Doxxing and Identity-Chain Risks
Ransomware leaks rarely stop at one company’s files. Criminals frequently combine newly obtained data with information from previous breaches to build detailed profiles. A phone number from a LaRosa’s order paired with an email from an earlier retail breach can quickly link your online handles, social media accounts, and even children’s gaming profiles back to your real-world identity and home address. These identity chains make doxxing, targeted phishing, and account takeovers far easier. Credential leaks of this kind regularly cascade into gaming account compromises because the same passwords or recovery emails are reused across services.