< Back to all clusters
[TECHNOLOGY] · United States · 9 sources

started · updated

Medusa ransomware hits over 500 critical infrastructure organizations

Federal agencies, including CISA, the FBI, and the U.S. Department of Health and Human Services, have issued an updated advisory regarding the Medusa ransomware group. As of April 2026, the group has compromised more than 500 organizations across various critical infrastructure sectors, including healthcare, education, manufacturing, and legal services.

Medusa operates as a Ransomware-as-a-Service (RaaS) model, which transitioned from a closed operation in 2023. The group utilizes a double-extortion tactic: affiliates first exfiltrate sensitive data before encrypting systems, then threaten to leak or sell the stolen information on a Tor-based site if demands are not met. Investigators noted that the group often researches a victim's financial standing to tailor ransom demands based on reported revenue.

To increase pressure, Medusa employs strict deadlines and offers a one-day extension for a $10,000 cryptocurrency payment. The group is known for its speed, often weaponizing newly announced software vulnerabilities within 24 hours. While they do not appear to develop their own zero-day exploits, they are highly effective at leveraging existing vulnerabilities and recruiting initial access brokers to infiltrate corporate networks.

Entities

CISA · Cybersecurity and Infrastructure Security Agency · FBI · Federal Bureau of Investigation · Medusa · Microsoft · U.S. Department of Health and Human Services

Claims

What the coverage asserts, and how many sources carry each claim.