Medusa Ransomware Hits Over 500 Critical Infrastructure Organizations
The **Cybersecurity and Infrastructure Security Agency (CISA)**, in conjunction with the **Department of Health and Human Services (HHS)** and the **Federal Bureau of Investigation (FBI)**, has revealed that the **Medusa** ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. This updated advisory highlights the escalating threat posed by the group across multiple vital sectors, urging network defenders to bolster their security posture.

In a recent joint advisory, **CISA**, **HHS**, and the **FBI** disclosed that the **Medusa** ransomware operation has impacted over 500 critical infrastructure organizations across the U.S. since June 2021. This marks a significant increase from the 300 organizations reported in March 2025, signaling a growing and persistent threat.
### Broad Sector Impact
The affected sectors are diverse and critical to national functions, including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. Beyond these, organizations in medical, education, legal, insurance, technology, and manufacturing industries have also fallen victim.
### Recommendations for Network Defenders
Federal agencies are urging network defenders to take proactive measures to secure their environments. Key recommendations include mitigating security vulnerabilities to protect operating systems, software, and firmware from exploitation. Additionally, security teams are advised to segment networks to prevent lateral movement post-compromise and to block access from untrusted sources to remote services on internal systems.
### Medusa's Evolution and Tactics
The **Medusa** ransomware operation first appeared in January 2021. Its activity notably escalated in 2023 with the launch of the Medusa Blog leak site, where stolen data is published to pressure victims into paying ransoms.
Initially a closed variant, **Medusa** has evolved into a **Ransomware-as-a-service (RaaS)** model, adopting an affiliate program. The advisory notes that **Medusa** developers actively recruit initial access brokers (**IABs**) through cybercriminal forums, offering substantial payments ranging from $100 USD to $1 million USD for exclusive access to potential victims.
### Distinguishing Medusa from Other Threats
It's important to differentiate this **Medusa** ransomware operation from other similarly named malware families and cybercrime activities. These include a **Mirai**-based botnet with ransomware capabilities and an Android malware-as-a-service (**MaaS**) operation (also known as **TangleBot**) discovered in 2020. Confusion has also arisen with the distinct **MedusaLocker** ransomware operation.
**Medusa** garnered significant media attention in March 2023 following an attack on the **Minneapolis Public Schools (MPS)** district, where the group posted a video showcasing stolen data as proof of compromise.