Medusa Ransomware Escalates Threat to US Critical Infrastructure
500+ Organizations Hit as Medusa Ransomware Tightens Grip on US Critical Infrastructure
Key Details of the Medusa Ransomware Campaign
The US Cybersecurity and Infrastructure Security Agency (CISA) reported that the Medusa ransomware campaign has compromised over 500 critical infrastructure entities in the United States since June 2021. This information was disclosed in a collaborative advisory issued by CISA in partnership with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI). The agencies confirmed that more than 500 affected organizations across multiple critical infrastructure sectors were identified as of April 2026.
Targeted Sectors and Industries
The advisory highlighted that Medusa ransomware has targeted entities within the Healthcare and Public Health sector, the Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. Additional impacted organizations include those in the medical, education, legal, insurance, technology, and manufacturing industries, underscoring the extensive scope of the ransomware operation.
Escalation and Evolution of the Campaign
A previous joint report from March 2025 estimated that Medusa had affected over 300 critical infrastructure organizations. The recent update to over 500 victims indicates a substantial escalation in the campaign’s reach, emphasizing the persistent danger posed by ransomware-driven extortion efforts.
Medusa’s Origins and RaaS Model
Medusa first appeared in January 2021, with a notable surge in activity during 2023. During this period, the group launched the Medusa Blog leak site, utilizing stolen data as additional leverage against victims. Ransomware groups frequently employ data theft and threats of public disclosure to pressure organizations into paying ransoms. Initially operating as a closed ransomware group, Medusa transitioned into a Ransomware-as-a-Service (RaaS) model. This structure allows developers to collaborate with affiliates who assist in gaining access to targets, deploying ransomware, and executing attacks.
Security Recommendations for Organizations
According to the advisory, Medusa operators typically recruit Initial Access Brokers (IABs) through cybercrime forums and marketplaces to secure initial entry points into potential victims’ networks. Affiliates may receive payments ranging from $100 to $1 million, with some opportunities offering exclusive roles within the Medusa operation. US cybersecurity agencies have urged network defenders to mitigate risks by addressing vulnerabilities in operating systems, software, and firmware. Timely application of security patches and updates can minimize opportunities for attackers to exploit known weaknesses and infiltrate corporate networks. Organizations are also advised to restrict access to remote services from untrusted sources. Implementing robust controls for remote access can reduce the likelihood of attackers leveraging compromised credentials or exposed services to expand their presence within an environment.
Confusion with Other Malware Families
The Medusa ransomware operation has sparked confusion within the cybersecurity community due to its name being associated with multiple malware families and cybercrime activities. These include a Mirai-based botnet with ransomware capabilities and an Android Malware-as-a-Service operation. The Medusa ransomware group must not be conflated with the well-known MedusaLocker ransomware operation, as they are distinct entities.
Notable Attacks and Recent Developments
The Medusa campaign gained significant attention in March 2023 after claiming responsibility for an attack on the Minneapolis Public Schools district, accompanied by a video allegedly showcasing stolen data. The latest warning underscores the threat’s expansion beyond traditional business networks, affecting organizations critical to essential services and infrastructure. Attacks on healthcare, government, defense, financial services, and manufacturing entities risk disrupting operations while exposing sensitive corporate, personal, and operational data.
Continued Monitoring and Mitigation Efforts
CISA, FBI, and HHS continue to monitor the threat and have encouraged organizations to enhance vulnerability management, network segmentation, and remote-access security measures. For critical infrastructure operators, maintaining updated systems and limiting unnecessary network access remain vital steps in mitigating the potential impact of ransomware attacks.
“The Medusa ransomware group must not be conflated with the well-known MedusaLocker ransomware operation, as they are distinct entities.”
