CISA: Medusa ransomware hit over 500 critical infrastructure orgs
by Sergiu Gatlan · BleepingComputerThe Cybersecurity and Infrastructure Security Agency (CISA) said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.
This was revealed in a joint advisory in coordination with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI).
"As of April 2026, Medusa actors have impacted more than 500 victims across multiple critical infrastructure sectors, including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services," they said.
"Other victims include organizations in the medical, education, legal, insurance, technology, and manufacturing industries."
This is an update to a joint report published in March 2025, which said the Medusa ransomware operation had impacted an estimated over 300 critical infrastructure organizations.
The three federal agencies recommended that network defenders secure their networks against the ransomware group's attacks by mitigating security vulnerabilities to protect operating systems, software, and firmware from exploitation attempts.
Security teams are also advised to segment networks to block lateral movement after compromise and to block access from untrusted origins to remote services on internal systems.
Active since January 2021
The Medusa ransomware operation surfaced five years ago, in January 2021. Still, the gang's activity only picked up in 2023 after launching the Medusa Blog leak site and began using stolen data as leverage to pressure victims into paying ransoms.
Medusa emerged as a closed ransomware variant, but it evolved into a Ransomware-as-a-service (RaaS) operation and adopted an affiliate model.
"Medusa developers typically recruit initial access brokers (IABs) in cybercriminal forums and marketplaces to obtain initial access to potential victims," the advisory says. "Potential payments between $100 USD and $1 million USD are offered to these affiliates with the opportunity to work exclusively for Medusa."
Medusa is a common name among malware families and cybercrime operations, including a Mirai-based botnet with ransomware capabilities and an Android malware-as-a-service (MaaS) operation discovered in 2020 and also tracked as TangleBot.
Because of this, reporting on Medusa ransomware has also often been ambiguous, with many confusing it with the widely known MedusaLocker ransomware operation, even though they are different operations.
The Medusa cybercrime operation gained media attention in March 2023 after claiming an attack on the Minneapolis Public Schools (MPS) district and sharing a video of the stolen data.
Once attackers have valid credentials, only 37% of their actions are blocked
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.