Medusa Ransomware Has Hit 500+ Critical Infrastructure Orgs, CISA Warns

Medusa ransomware CISA advisory critical infrastructure attacks RaaS

The Medusa threat group has attacked more than 500 U.S. critical infrastructure organizations since June 2021. As recently as February 2025, American authorities had counted just over 300 confirmed victims, meaning the roster of known casualties has grown by at least two hundred in the time since. The updated figures appear in a newly revised joint advisory published by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the U.S. Department of Health and Human Services (HHS) on defending against the ransomware.

Sectors Targeted Through April 2026

As of April 2026, Medusa has successfully infiltrated networks belonging to healthcare organizations, the defense industrial base, critical manufacturing, government services, the IT sector, and financial institutions. The victim list also includes medical and educational institutions, legal and insurance firms, technology companies, and manufacturing organizations.

An Updated Advisory – and a Growing Victim Count

The previous version of the joint advisory from CISA, the FBI, and HHS was published in March 2025. At that time, the agencies reported more than 300 victims among critical infrastructure organizations, with the statistics covering Medusa’s developers as well as their affiliated partners.

From Closed Operation to Public Extortion Site

Medusa first emerged in January 2021, though the group’s activity accelerated noticeably starting in 2023. Its operators launched the Medusa Blog, a site where they publish information about compromised organizations and stolen files. Encryption of corporate data was subsequently supplemented by leak-threat pressure: attackers first steal information, then demand payment in exchange for not publishing it.

Medusa drew widespread attention following its attack on the Minneapolis school district in March 2023. After the breach, the attackers posted a video demonstrating the stolen materials. That campaign illustrated Medusa’s double-extortion approach in practice: locking victims out of their data while simultaneously threatening to expose information already copied beforehand, should the organization refuse to pay.

From Closed Shop to Ransomware-as-a-Service

The group’s operating model has also evolved considerably over the past several years. Medusa began as a closed operation running its own proprietary encryptor, later transitioning to a Ransomware-as-a-Service (RaaS) model. Under this arrangement, developers supply the malware and supporting infrastructure to affiliates, while individual partners handle target selection, network infiltration, and further attack development.

Initial Access Brokers Fuel the Operation

To gain initial footholds, Medusa actively relies on Initial Access Brokers (IABs). These intermediaries pre-compromise corporate networks or obtain valid credentials, then sell that access to other cybercriminals. Medusa’s developers recruit brokers through criminal forums and underground marketplaces. According to the joint advisory from U.S. agencies, affiliates are offered payments ranging from $100 to $1 million, including bonuses for exclusive partnership arrangements.

This division of labor significantly accelerates attacks. Medusa’s operators no longer need to independently locate a vulnerable server, steal an employee’s password, or devise another means of entry each time. With ready-made access already in hand, attack participants can escalate privileges, map the internal network, pivot between systems, reach servers and data repositories, exfiltrate information, and prepare systems for encryption.

Recommended Defensive Measures

CISA, the FBI, and HHS recommend prioritizing the patching of known vulnerabilities in operating systems, application software, and device firmware. A single vulnerable component can hand attackers their initial foothold, from which the attack then unfolds deeper within the corporate network. The original CISA advisory separately catalogued Medusa’s specific tactics and techniques, along with measures organizations can take to complicate the group’s operations.

Network segmentation represents another important protective measure. Dividing infrastructure into isolated zones prevents an attacker who has compromised one machine from freely moving toward neighboring systems – a stage of attack known as lateral movement, in which the attacker leverages an already-compromised host, stolen credentials, and available network connections to gradually expand control over the infrastructure. U.S. agencies also advise restricting access to remote services on internal systems and blocking connections originating from untrusted sources.

Avoiding Confusion With Similarly Named Threats

The name Medusa warrants a specific clarification, given the existence of several unrelated malicious projects that share it. There is a separate Medusa botnet built on the Mirai codebase with ransomware-like functionality, as well as an Android malware discovered in 2020 that also goes by the name TangleBot among others. A shared name does not indicate any connection to the same threat group.

Medusa is also frequently confused with MedusaLocker. MedusaLocker predates Medusa and belongs to an entirely separate operation, with its own distinct history, infrastructure, and malware. This U.S. advisory concerns specifically the Medusa group that began operating in 2021, launched its Medusa Blog leak site in 2023, and later transitioned to the RaaS affiliate model.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply