started · updated
Medusa ransomware hits over 500 critical infrastructure organizations
Federal agencies, including CISA, the FBI, and the U.S. Department of Health and Human Services, have issued an updated advisory regarding the Medusa ransomware group. As of April 2026, the group has compromised more than 500 organizations across various critical infrastructure sectors, including healthcare, education, manufacturing, and legal services.
Medusa operates as a Ransomware-as-a-Service (RaaS) model, which transitioned from a closed operation in 2023. The group utilizes a double-extortion tactic: affiliates first exfiltrate sensitive data before encrypting systems, then threaten to leak or sell the stolen information on a Tor-based site if demands are not met. Investigators noted that the group often researches a victim's financial standing to tailor ransom demands based on reported revenue.
To increase pressure, Medusa employs strict deadlines and offers a one-day extension for a $10,000 cryptocurrency payment. The group is known for its speed, often weaponizing newly announced software vulnerabilities within 24 hours. While they do not appear to develop their own zero-day exploits, they are highly effective at leveraging existing vulnerabilities and recruiting initial access brokers to infiltrate corporate networks.
Entities
CISA · Cybersecurity and Infrastructure Security Agency · FBI · Federal Bureau of Investigation · Medusa · Microsoft · U.S. Department of Health and Human Services
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] Medusa transitioned to a Ransomware-as-a-Service (RaaS) model in 2023. cybersecuritynews.com · therecord.media
- [● 2 SOURCES] Medusa actors can weaponize newly announced vulnerabilities within 24 hours. healthsystemcio.com · therecord.media
- [● 2 SOURCES] There is no way to verify that stolen data is actually deleted after a ransom is paid. www.security.nl · healthsystemcio.com
- [● 4 SOURCES] Medusa actors research victim finances and size demands against publicly posted revenue. www.security.nl · healthsystemcio.com · cybersecuritynews.com · therecord.media
- [● 4 SOURCES] Medusa operates using a double-extortion model, stealing data before applying encryption. www.security.nl · healthsystemcio.com · cybersecuritynews.com · therecord.media
- [● 4 SOURCES] Medusa offers victims a one-day extension on leak countdowns for $10,000 in cryptocurrency. www.security.nl · healthsystemcio.com · cybersecuritynews.com · therecord.media
- [● 4 SOURCES] Medusa has targeted sectors including healthcare, education, legal services, insurance, technology, and manufacturing. www.security.nl · healthsystemcio.com · cybersecuritynews.com · therecord.media
- [● 4 SOURCES] Medusa ransomware has compromised more than 500 organizations across critical infrastructure sectors. www.security.nl · healthsystemcio.com · cybersecuritynews.com · therecord.media