
A joint advisory from the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, and the Department of Health and Human Services says the Medusa ransomware group has affected more than 500 organizations across U.S. critical infrastructure sectors since June 2021. The update replaces an earlier March 2025 assessment that placed the figure above 300 victims.
The agencies list healthcare and public health, defense industrial base, critical manufacturing, government services and facilities, information technology, and financial services among the sectors hit. Victims also include organizations in medical, education, legal, insurance, technology, and manufacturing industries.
The advisory recommends several defensive measures. Network defenders should patch operating system, software, and firmware vulnerabilities to reduce exploitation. They should segment networks to stop lateral movement after an intrusion, and restrict remote access from untrusted sources to internal services.
Medusa first appeared in January 2021, according to the advisory. Its activity grew in 2023 after the group created a leak site and began using stolen data as leverage to force ransom payments. Initially a closed ransomware variant, Medusa evolved into a ransomware-as-a-service operation with an affiliate model. The advisory notes that Medusa developers typically recruit initial access brokers on cybercriminal forums and marketplaces, offering between $100 and $1 million for initial access to potential victims.
The Medusa name is shared with other malware families, including a Mirai-based botnet with ransomware features and an Android malware-as-a-service operation discovered in 2020 and also tracked as TangleBot. This overlap has led to ambiguous reporting and frequent confusion between Medusa and the separate MedusaLocker ransomware operation, the advisory explains.
Medusa gained media attention in March 2023 after claiming an attack on Minneapolis Public Schools and posting video of stolen data, according to the report.
The agencies released the alert on Tuesday. The updated figures show a rise from the estimate of more than 300 victims published in March 2025, suggesting the ransomware operation remains active. The advisory does not name most victims, but the Minneapolis Public Schools incident from March 2023 is cited as an example of the group's public extortion tactics.
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST

