CISA Warns Medusa Ransomware Has Breached Over 500 Critical Infrastructure Targets
The Cybersecurity and Infrastructure Security Agency (CISA), in a joint advisory with the FBI and the Department of Health and Human Services, announces that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. The victims span multiple sectors, including Healthcare and Public Health, the Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. The advisory updates a March 2025 report that previously linked the gang to over 300 victims.
The Medusa operation first surfaces in January 2021, but its activity accelerates in 2023 after the gang launches its Medusa Blog leak site and begins using stolen data to pressure victims into paying ransoms. Originally a closed ransomware variant, Medusa evolves into a Ransomware-as-a-Service operation with an affiliate model. The gang's developers recruit initial access brokers on cybercriminal forums, offering payments ranging from $100 to $1 million for access to potential victims.
The federal agencies recommend that network defenders mitigate security vulnerabilities in operating systems, software, and firmware to prevent exploitation. They also advise segmenting networks to block lateral movement after a compromise and restricting access to remote services on internal systems from untrusted origins. The advisory warns that the name Medusa refers to multiple unrelated malware families, which can complicate accurate reporting and attribution.