Medusa ransomware has hit 500 critical infrastructure targets, US agencies warn

A fresh CISA advisory says the gang's victim count has jumped from 300 to over 500, with hospitals, defence suppliers and banks all in the firing line.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A map of critical infrastructure across the United States—hospitals, power plants, banks, defense facilities—with 500 location markers indicating Medusa ransomw
Share

Key points - CISA, the FBI and the Department of Health and Human Services said on Tuesday that Medusa ransomware has hit more than 500 critical infrastructure organisations in the United States since June 2021. - The victim count rose from roughly 300 in a March 2025 advisory to over 500 as of April 2026. - Affected sectors include healthcare, defence manufacturing, government services and financial services, among others. - Medusa now runs as a ransomware-as-a-service operation, paying affiliates between $100 and $1 million per successful break-in. - Weak authentication and unpatched public-facing systems are recurring themes in how Medusa gets inside.

American cyber authorities have issued a blunt update on one of the busiest ransomware crews around. Medusa, a criminal group that encrypts a victim's files and demands payment to restore them, has now hit more than 500 organisations running essential services.

The figure comes from a joint advisory published by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI and the Department of Health and Human Services. It updates a March 2025 bulletin that put the count at roughly 300. That's 200 more known victims in about a year.

Who has Medusa been hitting?

The advisory names critical infrastructure sectors: hospitals and clinics, defence manufacturers, government offices, IT providers and financial firms. Schools, legal practices and insurers also appear on the list, first reported by BleepingComputer.

Medusa first surfaced in January 2021 as a closed ransomware variant run by one group. Activity picked up in 2023 when the gang launched a public leak site, posting stolen files to pressure victims into paying.

It's since become a ransomware-as-a-service operation, with core developers renting the malware to outside criminals known as affiliates who keep a share of each ransom. We've followed the RaaS model across six stories on this site since June, and the affiliate economics keep looking more attractive as gangs compete for access.

How does the group get in?

Medusa's developers recruit "initial access brokers" on criminal forums. These are hackers with one job: break into a network and sell that foothold. The advisory says brokers are offered between $100 and $1 million per usable access, with a bonus for working exclusively with Medusa. Once inside, affiliates encrypt data and start the extortion.

Those brokers lean heavily on stolen or reused credentials for VPNs and remote desktop services. Adding a second authentication factor, such as a one-time code on top of a password, raises the cost of that approach sharply and is the single most practical control for organisations exposed here.

The three agencies recommend patching operating systems and firmware, splitting networks into smaller zones so an intruder can't move freely, and blocking remote access from untrusted locations.

What the numbers look like

Metric Value
Victims by March 2025 ~300
Victims by April 2026 500+
Active since January 2021
Leak site launched 2023
Affiliate payouts $100 to $1,000,000

Why the name keeps causing confusion

"Medusa" is a crowded label in cybercrime. There's an Android banking malware called Medusa (also known as TangleBot), a Mirai-based botnet using the name, and a separate ransomware crew called MedusaLocker. None are the same group covered in this advisory.

The ransomware Medusa grabbed wider attention in March 2023 after claiming a break-in at Minneapolis Public Schools and posting a video that flicked through stolen files.

Should you worry if your provider is on the list?

If your hospital, school or employer has been hit by Medusa, expect delays and, in some cases, letters confirming personal data was taken. Change passwords on any account tied to that organisation and turn on multi-factor authentication where it's offered. Treat unexpected emails or calls referencing the breach with suspicion: criminals routinely follow up with scams aimed at people already shaken by the news.

The honest read on this advisory is that a count rising from 300 to over 500 in roughly a year isn't evidence Medusa is getting more sophisticated. It means the affiliate model is working as designed, lowering the skill floor while spreading the operational risk across dozens of independent actors. That's what makes it harder to disrupt than a single tightly-run crew.

© 2026 Threat Vectr