The CISA said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.
The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS) are releasing this updated joint advisory to disseminate known Medusa ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as April 2026. Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. Both Medusa developers and affiliates use a double-extortion model where they encrypt victim data and threaten to publicly release exfiltrated data if a ransom is not paid.
Commenting on this is Rebecca Moody, Head of Data Research at Comparitech:
“Since Medusa first started adding victims to its data leak site in early 2023, we’ve logged just over 500 attacks in total (across all sectors and countries). As the figure is similar to CISA’s, this demonstrates how many ransomware victims slip under the radar, either because ransom negotiations are successful and the entity isn’t added to the group’s data leak site and/or the attack isn’t acknowledged/publicized by the entity involved.
To date, 162 organizations worldwide have confirmed attacks via Medusa and 100 of these are US-based. Of the confirmed US victims, 14 are government organizations, 25 are healthcare providers, seven are finance companies, three are tech companies, and four are manufacturers (two of which would be classed as critical infrastructure).”
The CISA has mitigation strategies that do work. I strongly suggest that you read and implement them ASAP or you could be Medusa’s next victim.
UPDATE: John Strand, Owner, Black Hills Information Security, Inc. had this to say:
“It’s kind of refreshing to get back to a good old-fashioned ransomware story instead of everything being about AI. But I have a sneaking suspicion there’s some AI lurking underneath the surface here. The fact that attackers were exploiting vulnerabilities up to two weeks before patches were available tells me we’re either dealing with some incredibly talented security researchers and exploit developers, or AI is helping accelerate that process. Possibly both.
“The other concerning part of this story is the continued focus by ransomware groups on critical infrastructure and healthcare. If attackers can disrupt a municipality, hospital, or another organization that serves a large community, they can create tremendous pressure that goes far beyond the financial impact on the organization itself. The dinner bell has been rung.
“Attackers have figured out that these organizations can be lucrative targets because the people making the decision about whether to pay aren’t just answering to employees or shareholders. They’re answering to entire communities that may depend on those systems and services.”
Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:
“Medusa is a good example of how ransomware operations have evolved beyond simply encrypting systems. When attackers can exploit a newly disclosed vulnerability within 24 hours, or potentially exploit it before it is even publicly disclosed, traditional patching cycles are no longer enough.
“Organizations need to know exactly what they have exposed to the internet, prioritize those systems for rapid remediation, and have compensating controls in place when a patch isn’t available. The reported triple-extortion tactics also reinforce an important point: paying a ransom does not guarantee the incident is over. Attackers may come back for more, which makes resilient backups, segmentation, detection, and a tested incident response plan more important than ever.”
Damon Small, Board of Directors, Xcape, Inc.:
“Rapid exploitation of perimeter vulnerabilities by Medusa ransomware operators presents an enduring operational risk to healthcare and critical infrastructure providers, where unexpected downtime threatens essential public services.
“While the group occasionally weaponizes flaws shortly before or after public disclosure, its primary entry point remains well-known vulnerabilities on Internet-facing software for which patches already exist. As CISA and the FBI highlight, these threat actors intentionally target organizations that often lack dedicated cybersecurity teams. However, an absence of specialized security staff does not excuse neglecting fundamental IT administration.
“Virtually all targeted entities employ internal or third-party system administrators whose core capability and job responsibility includes basic software maintenance and routine patching. Ransomware will remain a pervasive and lucrative threat as long as the industry fails to execute basic hygiene. Security leaders and IT managers must enforce strict patching SLAs on all edge assets, mandate rigid network segmentation around sensitive workloads, and maintain immutable offline backups to resist multi-stage extortion tactics.
“Critical Takeaways
- Hygiene failure: Medusa primarily weaponizes well-known, patchable vulnerabilities on Internet-facing systems rather than relying strictly on complex zero-days.
- Administrative accountability: Lacking a dedicated security operations team does not absolve internal or third-party sysadmins from performing fundamental software maintenance.
- Extortion escalation: Threat actors are increasingly turning to multi-stage extortion and re-extorting victims who pay, making immutable off-grid backups essential.
“Ransomware operators do not need cutting-edge exploits when our industry refuses to perform routine IT maintenance.”
Seemant Sehgal, Founder & CEO, BreachLock:
“Medusa’s activity is a reflection of how quickly today’s threat actors can move from identifying an opportunity to acting on it. The takeaway for defenders is that speed and visibility have become powerful advantages in security programs.
“Teams that continuously understand their internet-facing exposure, prioritize rapid remediation, and maintain strong operational discipline are in a much better position to stay ahead of emerging threats.
“The reported triple-extortion case is also a reminder that resilience is paramount. Effective recovery plans, tested response processes, and business continuity preparation give organizations options and control when facing a ransomware event.”
Related
This entry was posted on August 19, 2026 at 1:31 pm and is filed under Commentary with tags CISA. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
The CISA warns Medusa ransomware has hit over 500 critical infrastructure organizations
The CISA said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021.
The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS) are releasing this updated joint advisory to disseminate known Medusa ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as April 2026. Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. Both Medusa developers and affiliates use a double-extortion model where they encrypt victim data and threaten to publicly release exfiltrated data if a ransom is not paid.
Commenting on this is Rebecca Moody, Head of Data Research at Comparitech:
“Since Medusa first started adding victims to its data leak site in early 2023, we’ve logged just over 500 attacks in total (across all sectors and countries). As the figure is similar to CISA’s, this demonstrates how many ransomware victims slip under the radar, either because ransom negotiations are successful and the entity isn’t added to the group’s data leak site and/or the attack isn’t acknowledged/publicized by the entity involved.
To date, 162 organizations worldwide have confirmed attacks via Medusa and 100 of these are US-based. Of the confirmed US victims, 14 are government organizations, 25 are healthcare providers, seven are finance companies, three are tech companies, and four are manufacturers (two of which would be classed as critical infrastructure).”
The CISA has mitigation strategies that do work. I strongly suggest that you read and implement them ASAP or you could be Medusa’s next victim.
UPDATE: John Strand, Owner, Black Hills Information Security, Inc. had this to say:
“It’s kind of refreshing to get back to a good old-fashioned ransomware story instead of everything being about AI. But I have a sneaking suspicion there’s some AI lurking underneath the surface here. The fact that attackers were exploiting vulnerabilities up to two weeks before patches were available tells me we’re either dealing with some incredibly talented security researchers and exploit developers, or AI is helping accelerate that process. Possibly both.
“The other concerning part of this story is the continued focus by ransomware groups on critical infrastructure and healthcare. If attackers can disrupt a municipality, hospital, or another organization that serves a large community, they can create tremendous pressure that goes far beyond the financial impact on the organization itself. The dinner bell has been rung.
“Attackers have figured out that these organizations can be lucrative targets because the people making the decision about whether to pay aren’t just answering to employees or shareholders. They’re answering to entire communities that may depend on those systems and services.”
Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:
“Medusa is a good example of how ransomware operations have evolved beyond simply encrypting systems. When attackers can exploit a newly disclosed vulnerability within 24 hours, or potentially exploit it before it is even publicly disclosed, traditional patching cycles are no longer enough.
“Organizations need to know exactly what they have exposed to the internet, prioritize those systems for rapid remediation, and have compensating controls in place when a patch isn’t available. The reported triple-extortion tactics also reinforce an important point: paying a ransom does not guarantee the incident is over. Attackers may come back for more, which makes resilient backups, segmentation, detection, and a tested incident response plan more important than ever.”
Damon Small, Board of Directors, Xcape, Inc.:
“Rapid exploitation of perimeter vulnerabilities by Medusa ransomware operators presents an enduring operational risk to healthcare and critical infrastructure providers, where unexpected downtime threatens essential public services.
“While the group occasionally weaponizes flaws shortly before or after public disclosure, its primary entry point remains well-known vulnerabilities on Internet-facing software for which patches already exist. As CISA and the FBI highlight, these threat actors intentionally target organizations that often lack dedicated cybersecurity teams. However, an absence of specialized security staff does not excuse neglecting fundamental IT administration.
“Virtually all targeted entities employ internal or third-party system administrators whose core capability and job responsibility includes basic software maintenance and routine patching. Ransomware will remain a pervasive and lucrative threat as long as the industry fails to execute basic hygiene. Security leaders and IT managers must enforce strict patching SLAs on all edge assets, mandate rigid network segmentation around sensitive workloads, and maintain immutable offline backups to resist multi-stage extortion tactics.
“Critical Takeaways
“Ransomware operators do not need cutting-edge exploits when our industry refuses to perform routine IT maintenance.”
Seemant Sehgal, Founder & CEO, BreachLock:
“Medusa’s activity is a reflection of how quickly today’s threat actors can move from identifying an opportunity to acting on it. The takeaway for defenders is that speed and visibility have become powerful advantages in security programs.
“Teams that continuously understand their internet-facing exposure, prioritize rapid remediation, and maintain strong operational discipline are in a much better position to stay ahead of emerging threats.
“The reported triple-extortion case is also a reminder that resilience is paramount. Effective recovery plans, tested response processes, and business continuity preparation give organizations options and control when facing a ransomware event.”
Share this:
Like this:
Related
This entry was posted on August 19, 2026 at 1:31 pm and is filed under Commentary with tags CISA. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.