
The Cybersecurity and Infrastructure Safety Company (CISA) stated Tuesday that the Medusa ransomware gang has breached greater than 500 vital infrastructure organizations in the US since June 2021.
This was revealed in a joint advisory in coordination with the Division of Well being and Human Providers (HHS) and the Federal Bureau of Investigation (FBI).
“As of April 2026, Medusa actors have impacted greater than 500 victims throughout a number of vital infrastructure sectors, together with Healthcare and Public Well being, Protection Industrial Base, Vital Manufacturing, Authorities Providers and Amenities, Info Expertise, and Monetary Providers,” they said.
“Different victims embrace organizations within the medical, schooling, authorized, insurance coverage, expertise, and manufacturing industries.”
That is an replace to a joint report published in March 2025, which stated the Medusa ransomware operation had impacted an estimated over 300 vital infrastructure organizations.
The three federal businesses really helpful that community defenders safe their networks in opposition to the ransomware group’s assaults by mitigating safety vulnerabilities to guard working programs, software program, and firmware from exploitation makes an attempt.
Safety groups are additionally suggested to phase networks to dam lateral motion after compromise and to dam entry from untrusted origins to distant providers on inside programs.
Lively since January 2021
The Medusa ransomware operation surfaced 5 years in the past, in January 2021. Nonetheless, the gang’s exercise solely picked up in 2023 after launching the Medusa Weblog leak web site and started utilizing stolen knowledge as leverage to strain victims into paying ransoms.
Medusa emerged as a closed ransomware variant, but it surely developed right into a Ransomware-as-a-service (RaaS) operation and adopted an affiliate mannequin.
“Medusa builders sometimes recruit preliminary entry brokers (IABs) in cybercriminal boards and marketplaces to acquire preliminary entry to potential victims,” the advisory says. “Potential funds between $100 USD and $1 million USD are provided to those associates with the chance to work completely for Medusa.”
Medusa is a standard title amongst malware households and cybercrime operations, together with a Mirai-based botnet with ransomware capabilities and an Android malware-as-a-service (MaaS) operation found in 2020 and in addition tracked as TangleBot.
Due to this, reporting on Medusa ransomware has additionally usually been ambiguous, with many complicated it with the broadly identified MedusaLocker ransomware operation, although they’re completely different operations.
The Medusa cybercrime operation gained media consideration in March 2023 after claiming an attack on the Minneapolis Public Schools (MPS) district and sharing a video of the stolen knowledge.
General prevention scores can disguise what occurs after preliminary entry. As soon as attackers are utilizing legitimate credentials, prevention drops sharply.
The Blue Report 2026 measures defenses method by method throughout 338 million simulations run in buyer manufacturing environments.

