The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that the Medusa ransomware operation has impacted more than 500 critical infrastructure organizations in the United States since June 2021. The disclosure came in a joint advisory issued by CISA, in coordination with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI), confirming that more than 500 victims across multiple critical infrastructure sectors had been affected as of April 2026.
A Wide-Reaching Threat Across Sectors
The joint advisory said Medusa ransomware had targeted organizations operating in Healthcare and Public Health, the Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. Other affected victims included organizations in the medical, education, legal, insurance, technology, and manufacturing sectors, highlighting just how broad this ransomware operation's reach has become.
This latest advisory updates a joint report issued in March 2025, which had estimated Medusa had affected more than 300 critical infrastructure organizations at that point. The jump to over 500 victims signals a significant expansion of the ransomware operation, underlining the continuing threat posed by malware-based extortion campaigns of this scale.
How Medusa Evolved Since 2021
The Medusa ransomware operation first emerged in January 2021, though its activity increased significantly by 2023. During that period, the operators launched the Medusa Blog leak site and began using stolen data as additional leverage against victims, a fairly common tactic where ransomware groups threaten to publish sensitive information to pressure organizations into paying ransom demands.
Medusa initially operated as a closed ransomware group but later evolved into a Ransomware-as-a-Service (RaaS) operation. Under this model, ransomware developers work with affiliates who help obtain access to victims, deploy the ransomware itself, and carry out attacks against targeted organizations.
According to the joint advisory, Medusa operators typically recruit Initial Access Brokers (IABs) through cybercrime forums and marketplaces to gain initial access to potential victims. The advisory noted that affiliates could reportedly be offered payments ranging from 100 dollars to 1 million dollars, with some opportunities involving exclusive work solely for the Medusa operation.
What Cybersecurity Agencies Are Recommending
US cybersecurity agencies have advised network defenders to strengthen their systems against Medusa attacks by addressing security vulnerabilities in operating systems, software, and firmware. Promptly applying security updates and patches can meaningfully reduce opportunities for attackers to exploit known weaknesses and gain unauthorized access to corporate networks.
The agencies have also recommended network segmentation to restrict lateral movement following an initial compromise. By separating critical systems and network environments, organizations can make it considerably harder for attackers who gain access to one device or segment to move deeper into the broader network.
Organizations have additionally been advised to restrict access to remote services on internal systems from untrusted sources. Strong controls around remote access can help reduce the risk of attackers using compromised credentials or exposed services to expand their presence within an affected environment.
Medusa Is Not the Same as MedusaLocker
The name Medusa has also caused some confusion within the cybersecurity community, since it's been used by multiple malware families and cybercrime operations. These include a Mirai-based botnet with ransomware capabilities and an Android Malware-as-a-Service operation. It's worth being clear that the Medusa ransomware operation should not be confused with the widely known MedusaLocker ransomware group, as they are entirely separate operations, despite the similar naming.
The Medusa cybercrime operation received significant attention in March 2023, after claiming an attack against the Minneapolis Public Schools district and releasing a video that allegedly showed stolen data, an incident that helped bring wider public awareness to the group's activities.
A Threat That Extends Beyond Business Networks
This latest warning demonstrates that the Medusa ransomware threat extends well beyond conventional business networks and can affect organizations responsible for essential services and infrastructure. Attacks against healthcare, government, defense, financial services, and manufacturing organizations can potentially disrupt operations while also exposing sensitive corporate, personal, and operational information.
CISA, FBI, and HHS continue monitoring this threat and have urged organizations to strengthen vulnerability management, network segmentation, and remote-access security. For critical infrastructure operators specifically, maintaining updated systems and limiting unnecessary network access remain important, practical measures for reducing the potential impact of ransomware attacks like these.
FAQs
Q1. How many organizations has the Medusa ransomware operation affected?
More than 500 critical infrastructure organizations in the United States have been affected since June 2021, according to a joint advisory from CISA, HHS, and the FBI as of April 2026.
Q2. How does the Medusa ransomware operation typically gain access to victims?
Medusa operators typically recruit Initial Access Brokers through cybercrime forums and marketplaces to obtain initial access, offering affiliates payments ranging from 100 dollars to 1 million dollars.
Q3. Is Medusa the same as MedusaLocker ransomware?
No, despite the similar name, Medusa is a completely separate ransomware operation from the widely known MedusaLocker ransomware group.