Tuesday, August 25, 2026

Independent technology reporting and practical analysis

Manila ·
CYBERSECURITY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Cybersecurity / news

Medusa Ransomware Hits Over 500 US Critical Infrastructure Groups, CISA Warns

A joint federal advisory says the Medusa operation has affected more than 500 organizations since 2021, with healthcare, government and defense among sectors targeted.

Featured image for Medusa Ransomware Hits Over 500 US Critical Infrastructure Groups, CISA Warns
Featured image for Medusa Ransomware Hits Over 500 US Critical Infrastructure Groups, CISA Warns

A joint advisory from the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, and the Department of Health and Human Services says the Medusa ransomware group has affected more than 500 organizations across U.S. critical infrastructure sectors since June 2021. The update replaces an earlier March 2025 assessment that placed the figure above 300 victims.

The agencies list healthcare and public health, defense industrial base, critical manufacturing, government services and facilities, information technology, and financial services among the sectors hit. Victims also include organizations in medical, education, legal, insurance, technology, and manufacturing industries.

The advisory recommends several defensive measures. Network defenders should patch operating system, software, and firmware vulnerabilities to reduce exploitation. They should segment networks to stop lateral movement after an intrusion, and restrict remote access from untrusted sources to internal services.

Medusa first appeared in January 2021, according to the advisory. Its activity grew in 2023 after the group created a leak site and began using stolen data as leverage to force ransom payments. Initially a closed ransomware variant, Medusa evolved into a ransomware-as-a-service operation with an affiliate model. The advisory notes that Medusa developers typically recruit initial access brokers on cybercriminal forums and marketplaces, offering between $100 and $1 million for initial access to potential victims.

The Medusa name is shared with other malware families, including a Mirai-based botnet with ransomware features and an Android malware-as-a-service operation discovered in 2020 and also tracked as TangleBot. This overlap has led to ambiguous reporting and frequent confusion between Medusa and the separate MedusaLocker ransomware operation, the advisory explains.

Medusa gained media attention in March 2023 after claiming an attack on Minneapolis Public Schools and posting video of stolen data, according to the report.

The agencies released the alert on Tuesday. The updated figures show a rise from the estimate of more than 300 victims published in March 2025, suggesting the ransomware operation remains active. The advisory does not name most victims, but the Minneapolis Public Schools incident from March 2023 is cited as an example of the group's public extortion tactics.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Featured image for Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud
Cybersecurity

Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud

Philips LatteGo 4400 Series espresso machine on a kitchen counter.
Guides

Philips LatteGo 4400 espresso machine drops to AU$613 on Amazon Australia

Alice talks to Nora and Frank
Entertainment

How AI and assistive tools are helping disabled actors like Steve Way thrive on 'Furious'