CISA: Medusa ransomware hit over 500 critical infrastructure organizations

Medusa

The Cybersecurity and Infrastructure Security Agency (CISA) said on Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.

This was revealed in a joint consultation in coordination with the Federal Bureau of Investigation (FBI) and the Department of Health and Human Services (HHS).

“As of April 2026, Medusa participants have impacted more than 500 victims across multiple critical infrastructure sectors, including healthcare and public health, the defense industrial base, critical manufacturing, government services and facilities, information technology and financial services,” they said.

image

“Other victims include organizations in the medical, education, legal, insurance, technology and manufacturing industries.”

This is an update to a joint report released in March 2025 that said the Medusa ransomware operation affected approximately more than 300 critical infrastructure organizations.

The three federal agencies recommended that network defenders protect their networks against the ransomware group’s attacks by mitigating security vulnerabilities to protect operating systems, software and firmware from exploitation attempts.

Security teams are also advised to segment networks to block lateral movement after a compromise and block access from untrusted sources to remote services on internal systems.

Active from January 2021

The Medusa ransomware operation appeared five years ago, in January 2021. However, the gang’s activity did not become active until 2023, when it launched the Medusa blog leak site and began using stolen data as leverage to pressure victims into paying ransoms.

While Medusa emerged as a closed ransomware variant, it has evolved into a Ransomware-as-a-Service (RaaS) operation and adopted a partnership model.

“Medusa developers typically recruit Initial Access Brokers (IABs) on cybercriminal forums and marketplaces to gain initial access to potential victims,” ​​the advisory said. “Potential payouts between $100 USD and $1 million USD are offered to these affiliates with the opportunity to work exclusively for Medusa.”

Medusa is a common name among malware families and cybercrime operations, including an Android malware-as-a-service (MaaS) operation discovered in 2020 (also known as TangleBot) and a Mirai-based botnet with ransomware capabilities.

Because of this, the reporting of Medusa ransomware is also often confusing, with many believing it to be the same as the well-known MedusaLocker ransomware operation, even though they are completely different operations.

Cybercrime operation Medusa gained media attention in March 2023 after it claimed an attack on the Minneapolis Public Schools (MPS) district and shared a video of the stolen data.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *