According to a new warning from US authorities, the Medusa ransomware has breached more than 500 organizations, belonging to critical infrastructure in the United States, since June 2021. The disclosure by the Cybersecurity and Infrastructure Security Agency (CISA) demonstrates the extent of this threat and the increasing pressure on organizations with a critical role in the functioning of the American economy and society.
The advisory was issued jointly with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI), attempting to warn businesses and organizations that may be next targets.
From 300 to more than 500 victims
The new estimate shows a significant increase compared to the data that was made public in March 2025. At that time, US authorities had reported that Medusa activity had affected more than 300 critical infrastructure organizations.
See also: Cyberattack hits Ukrainian ARMA agency
By April 2026, the number had exceeded 500. The list includes health and public health organizations, defense industry companies, critical production units, government agencies, technology companies, and financial institutions.
The attacks are not limited to the above industries, however. Medical organizations, educational institutions, law firms, insurance companies, and manufacturing companies have also been targeted, proving that Medusa does not follow a narrow model of victim selection.

From ransomware to Ransomware-as-a-Service
Medusa made its appearance in January 2021, but its activity began to increase significantly from 2023. A decisive role in this development was played by the creation of the "Medusa Blog", a leak website where data from organizations that did not meet the demands of the perpetrators is published.
This tactic is a typical example of double blackmail. The attackers do not limit themselves to encrypting files, but also threaten to make the stolen data public, increasing the pressure on the victims.
At the same time, Medusa has evolved from a more closed operation to a Ransomware-as-a-Service (RaaS) model. This means that core administrators can work with external affiliates, who take over initial access and part of the operational process.
The affiliate ecosystem
According to the joint warning from the US agencies, the operators of Medusa use initial access intermediaries, known as Initial Access Brokers (IABs). These are cybercriminals who identify vulnerable networks or stolen credentials and then sell or hand over access to other groups.
See also: New waves of attacks on MLflow and FUXA – Critical vulnerabilities targeted
Associates can receive significant fees, ranging from around $100,000 to $1 million, which reveals the financial motivations behind this activity. This model allows Medusa to scale its operations without having to carry out every stage of an attack in-house.
CISA's key recommendations
CISA, FBI, and HHS urge cybersecurity leaders to limit potential entry routes as much as possible. Installing security updates and patching known vulnerabilities in operating systems, applications, and firmware are considered essential defenses.
At the same time, organizations are urged to implement network segmentationso that an initial breach does not allow easy lateral movement to critical systems. Of particular importance is limiting remote access to internal services from untrusted sources.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The logic is simple: even if an attacker manages to enter the network, they should not be able to move unhindered to the systems containing the most important data.

Confusion with other "Medusa" groups
Another problem is the naming. “Medusa” is used by different malware families and cybercriminal operations. There is, among others, botnet with ransomware capabilities, as well as an Android Malware-as-a-Service known as TangleBot.
Furthermore, this particular operation should not be confused with MedusaLocker, a different and widely known ransomware family.
See also: Pokémon Center: Data breach affects customers in Britain and Germany
Medusa gained international notoriety in March 2023, when it claimed responsibility for an attack on Minneapolis Public Schools and published material allegedly derived from stolen data.
The increase in victims shows that the threat remains active and evolving. For critical infrastructure organizations, protection is now not just about preventing an initial intrusion, but also the ability to contain the attack before it escalates into widespread outages or large-scale data breaches.
Source: www.bleepingcomputer.com
