CISA: Medusa ransomware hit over 500 critical infrastructure orgs
CISA, HHS, and FBI reported that the Medusa ransomware gang has breached over 500 critical infrastructure organizations in the United States since June 2021, an increase from a previous report.
Intelligence analysis by Gemini 2.5 Flash

A joint advisory from federal agencies revealed that the Medusa ransomware operation, active since January 2021, has significantly expanded its attacks, impacting a wide range of critical sectors. The group leverages a Ransomware-as-a-service model, recruiting initial access brokers and using stolen data to pressure victims into paying ransoms.
Imagine a sneaky group of digital bad guys called Medusa who are like digital burglars. They've broken into over 500 important places in the U.S., like hospitals, factories, and government offices, since 2021. They steal important computer files and then demand money to give them back, or they'll show everyone what they stole. The government is telling everyone how to put stronger locks and alarms on their digital doors to stop these burglars.
Analysis
The recent joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA), the Department of Health and Human Services (HHS), and the Federal Bureau of Investigation (FBI) serves as a critical update on the persistent threat of the Medusa ransomware group. This collaboration among federal agencies emphasizes the severity and widespread nature of the attacks, particularly targeting sectors vital to national security and public welfare. The advisory not only quantifies the impact but also provides actionable intelligence and recommendations for network defenders, aiming to fortify digital defenses against this evolving cyber threat.
Medusa Ransomware
The Medusa ransomware operation, which first emerged in January 2021, has significantly escalated its activities, particularly since 2023. This surge in activity coincided with the launch of the 'Medusa Blog' leak site, a common tactic used by ransomware gangs to publish stolen data and exert additional pressure on victims to pay ransoms. Initially a closed variant, Medusa has evolved into a Ransomware-as-a-service (RaaS) model, adopting an affiliate program that recruits initial access brokers (IABs). These IABs are offered substantial payments, ranging from $100 USD to $1 million USD, to gain initial access to potential victim networks, highlighting a sophisticated and financially motivated criminal enterprise.
500 Victims
The updated report indicates a concerning increase in the number of organizations impacted by Medusa, rising from an estimated 300 in March 2025 to over 500 by April 2026. This substantial growth in victim count underscores the group's effectiveness and the ongoing challenges faced by critical infrastructure sectors in defending against such attacks. The affected sectors are diverse and include Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. This broad targeting demonstrates Medusa's indiscriminate approach and its potential to disrupt a wide array of essential services, posing a significant risk to national stability and economic function.
January 2021
Since its inception in January 2021, the Medusa operation has demonstrated a consistent and adaptable threat. The federal agencies' recommendations focus on fundamental security practices that, if widely adopted, could significantly mitigate the risk. These include securing networks by addressing vulnerabilities in operating systems, software, and firmware, as well as implementing network segmentation to prevent lateral movement of attackers post-compromise. Blocking access from untrusted origins to remote services on internal systems is also crucial. The continued activity and increasing victim count since 2021 highlight that despite warnings and advisories, many organizations still struggle with implementing comprehensive security postures, making them susceptible to persistent and evolving ransomware threats like Medusa.
Key points
- Medusa ransomware has impacted over 500 critical infrastructure organizations in the U.S. since June 2021.
- The attacks target diverse sectors including healthcare, defense, manufacturing, government, IT, and financial services.
- The Medusa operation, active since January 2021, evolved into a Ransomware-as-a-service (RaaS) model, recruiting initial access brokers.
- Federal agencies (CISA, HHS, FBI) issued a joint advisory recommending network segmentation and vulnerability mitigation.
- The number of victims has increased from an estimated 300 in March 2025 to over 500 by April 2026.
The joint advisory from CISA, HHS, and FBI provides actionable recommendations for network defenders, suggesting that adherence to these security measures could significantly bolster defenses against Medusa and similar ransomware threats. Proactive implementation of network segmentation and vulnerability mitigation could reduce the attack surface and limit the impact of future breaches.
Despite federal warnings and mitigation advice, the Medusa ransomware group has continued to expand its reach, demonstrating an evolving threat model and the persistent challenge of securing critical infrastructure. The increase in victim count from 300 to over 500 suggests that current defenses are insufficient or not widely adopted, leaving many organizations vulnerable to ongoing exploitation.



