500+ Organizations Hit as Medusa Ransomware Tightens Grip on US Critical Infrastructure

The420.in Staff
5 Min Read

The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that the Medusa ransomware operation has impacted more than 500 critical infrastructure organizations in the United States since June 2021. The disclosure was made in a joint advisory issued by CISA in coordination with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI). According to the agencies, more than 500 victims across multiple critical infrastructure sectors had been affected as of April 2026.

The joint advisory said Medusa ransomware had targeted organizations operating in Healthcare and Public Health, the Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology and Financial Services. Other affected victims included organizations in the medical, education, legal, insurance, technology and manufacturing sectors, highlighting the broad reach of the ransomware operation.

FCRF Launches Flagship Certified Cyber Security Auditor (CCSA) Program for Next-Generation Cyber Auditors

The latest advisory updates a joint report issued in March 2025, which had estimated that Medusa had affected more than 300 critical infrastructure organizations. The increase to more than 500 victims indicates a significant expansion of the ransomware operation and underlines the continuing threat posed by malware-based extortion campaigns.

Medusa Emerged in 2021

The Medusa ransomware operation first emerged in January 2021, although its activity increased significantly in 2023. During that period, the operators launched the Medusa Blog leak site and began using stolen data as additional leverage against victims. Ransomware groups commonly use data theft and threats to publish sensitive information to pressure affected organizations into paying ransom demands.

Medusa initially operated as a closed ransomware group but later evolved into a Ransomware-as-a-Service (RaaS) operation. Under this model, ransomware developers work with affiliates who can assist with obtaining access to victims, deploying ransomware and conducting attacks against targeted organizations.

According to the joint advisory, Medusa operators typically recruit Initial Access Brokers (IABs) through cybercrime forums and marketplaces to obtain initial access to potential victims. The advisory said affiliates could reportedly be offered payments ranging from $100 to $1 million, with some opportunities involving exclusive work for the Medusa operation.

Agencies Warn Against Exploitable Vulnerabilities

US cybersecurity agencies have advised network defenders to strengthen their systems against Medusa attacks by addressing security vulnerabilities in operating systems, software and firmware. Promptly applying security updates and patches can reduce opportunities for attackers to exploit known weaknesses and gain unauthorized access to corporate networks.

The agencies have also recommended network segmentation to restrict lateral movement after an initial compromise. By separating critical systems and network environments, organizations can make it more difficult for attackers who gain access to one device or segment to move deeper into the network.

Organizations have additionally been advised to restrict access to remote services on internal systems from untrusted sources. Strong controls around remote access can help reduce the risk of attackers using compromised credentials or exposed services to expand their presence within an affected environment.

Medusa and MedusaLocker Are Different Operations

The name Medusa has also caused confusion within the cybersecurity community because it has been used by multiple malware families and cybercrime operations. These include a Mirai-based botnet with ransomware capabilities and an Android Malware-as-a-Service operation. The Medusa ransomware operation should therefore not be confused with the widely known MedusaLocker ransomware group, as they are separate operations.

The Medusa cybercrime operation received significant attention in March 2023 after claiming an attack against the Minneapolis Public Schools district and releasing a video that allegedly showed stolen data.

The latest warning demonstrates that the Medusa ransomware threat extends beyond conventional business networks and can affect organizations responsible for essential services and infrastructure. Attacks against healthcare, government, defense, financial services and manufacturing organizations can potentially disrupt operations while also exposing sensitive corporate, personal and operational information.

CISA, FBI and HHS are continuing to monitor the threat and have urged organizations to strengthen vulnerability management, network segmentation and remote-access security. For critical infrastructure operators, maintaining updated systems and limiting unnecessary network access remain important measures for reducing the potential impact of ransomware attacks.

Stay Connected