The Cybersecurity and Infrastructure Security Agency (CISA) says the Medusa ransomware group has compromised more than 500 critical infrastructure organizations in the United States since June 2021.
The disclosure was made in a joint cybersecurity advisory issued in coordination with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI).
“As of April 2026, the Medusa attackers have impacted more than 500 victims across multiple critical infrastructure sectors, including healthcare and public health, defense industrial base, critical manufacturing, government services and facilities, information technology, and financial services,” the agencies said in a related announcement.
The victims span a range of industries, including healthcare, education, legal services, insurance, technology, and manufacturing.
The latest figures update a joint report published in March 2025, which estimated that the Medusa ransomware operation had affected more than 300 critical infrastructure organizations.
CISA, HHS, and the FBI are urging organizations to strengthen their defenses against ransomware attacks by addressing known security vulnerabilities in operating systems, software, and firmware before attackers can exploit them.
The agencies also recommend segmenting networks to limit lateral movement after an initial breach and blocking access to internal remote services from untrusted sources.
Medusa ransomware has been active since January 2021
Medusa ransomware activity first emerged in January 2021. However, the cybercrime group became more prominent in 2023 after launching the Medusa Blog leak site and using stolen data to pressure victims into paying a ransom.
Medusa initially operated as a closed ransomware strain but later evolved into a ransomware-as-a-service (RaaS) operation that relies on affiliates.
“Medusa developers typically recruit Initial Access Brokers (IABs) on cybercrime forums and marketplaces to gain initial access to potential victims,” the advisory states. “These affiliates may be offered payments ranging from US$100 to US$1 million, along with the opportunity to work exclusively for Medusa.”
The name Medusa is also associated with several other malware and cybercrime operations, including a Mirai-based botnet with ransomware capabilities and an Android malware-as-a-service (MaaS) operation discovered in 2020 and also tracked as TangleBot.
Because multiple threats use the Medusa name, reports about Medusa ransomware have sometimes been unclear. The operation is also frequently confused with MedusaLocker, a separate and more widely known ransomware group.
The Medusa cybercrime operation gained widespread attention in March 2023 after claiming responsibility for an attack on the Minneapolis Public Schools (MPS) district and publishing a video showing allegedly stolen data.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




