Medusa ransomware has hit 500 critical infrastructure targets, US agencies warn

A fresh CISA advisory says the gang's victim count has jumped from 300 to over 500 since March 2025, with hospitals, defence suppliers and banks all in the firing line.

ThreatVectr Newsdesk· 4 min read
Photoreal editorial shot of a rack-mounted network security appliance in a dim server room, faint red status LEDs, ethernet cables trailing off frame, shallow d
Share

Key points

  • CISA, the FBI and the Department of Health and Human Services said on Tuesday that Medusa ransomware has hit more than 500 critical infrastructure organisations in the United States since June 2021.
  • The victim count has risen from about 300 in a March 2025 advisory to over 500 by April 2026.
  • Affected sectors include healthcare, defence manufacturing, government services, IT and financial services.
  • Medusa now runs as a ransomware-as-a-service operation, paying affiliates between $100 and $1 million per successful break-in.
  • The advisory does not name a single initial entry method, but weak authentication and unpatched public-facing systems are recurring themes in Medusa cases.

American cyber authorities have issued a blunt update on one of the busiest ransomware crews around. Medusa, a criminal group that scrambles a victim's files and demands payment to unlock them, has now hit more than 500 organisations that keep essential services running.

The figure comes from a joint advisory published by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI and the Department of Health and Human Services. It updates a March 2025 bulletin that put the count at roughly 300.

That is 200 more known victims in about a year.

Who has Medusa been hitting?

The advisory points to critical infrastructure sectors: hospitals and clinics, defence manufacturers, government offices, IT providers and financial firms. Schools, law firms and insurers also appear on the list, first reported by BleepingComputer.

Medusa first surfaced in January 2021 as a single ransomware strain run by one group. It went quiet, then re-emerged in 2023 with a public leak site where the gang posts stolen files to pressure victims into paying.

It has since become a ransomware-as-a-service operation. That means the core developers rent the malware to other criminals, called affiliates, and take a cut of any ransom paid.

How does the group get in?

Medusa's developers recruit "initial access brokers" on criminal forums. These are hackers who specialise in one job: breaking into a company's network and then selling that foothold to whoever will pay for it.

The advisory says brokers are offered between $100 and $1 million per usable access, with a bonus for working exclusively with Medusa. Once inside, affiliates deploy the ransomware, steal data, and start the extortion.

On the defence side, the three agencies recommend the usual, unglamorous basics: patch operating systems, software and firmware; split networks into smaller zones so an intruder in one area cannot roam freely; and block remote access from untrusted locations.

Would multi-factor authentication (the extra one-time code on top of a password) have helped? Honestly, in a lot of Medusa cases yes. Initial access brokers lean heavily on stolen or reused passwords for VPNs and remote desktop services. An extra factor at the door raises the cost of that trade sharply.

What the numbers look like

Metric Value
Victims by March 2025 ~300
Victims by April 2026 500+
Active since January 2021
Leak site launched 2023
Affiliate payouts $100 to $1,000,000

Why the name keeps causing confusion

"Medusa" is a crowded label in cybercrime. There is an Android banking malware called Medusa (also known as TangleBot), a Mirai-based botnet using the name, and a separate ransomware crew called MedusaLocker. None of these are the same group covered in this advisory.

The ransomware Medusa grabbed wider public attention in March 2023 after claiming a break-in at Minneapolis Public Schools and posting a video that flicked through the stolen files.

What should ordinary people do?

If your hospital, school district or employer has been hit by Medusa, expect delays and, in some cases, letters saying personal data was taken. Change passwords on any account tied to that organisation. Turn on multi-factor authentication where offered. Treat unexpected emails or calls referencing the breach with suspicion, because criminals often follow up with scams aimed at people already rattled by the news.

© 2026 Threat Vectr