Medusa Ransomware Is Back

Overview

The Cybersecurity and Infrastructure Security Agency (CISA), in coordination with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI), has confirmed that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. This marks a sharp increase from the 300 victims reported in March 2025, highlighting Medusa’s growing impact across essential sectors.

Scope of Impact

  • Healthcare & Public Health
  • Defense Industrial Base
  • Critical Manufacturing
  • Government Services & Facilities
  • Information Technology
  • Financial Services

Other victims include organizations in medical, education, legal, insurance, technology, and manufacturing industries.

Evolution of Medusa

  • Active since January 2021: Initially a closed ransomware variant.
  • 2023: Launched the Medusa Blog leak site, using stolen data to pressure victims.
  • Affiliate model: Transitioned into Ransomware‑as‑a‑Service (RaaS), recruiting initial access brokers with payments ranging from $100 to $1 million.
  • Confusion with MedusaLocker: Often misreported due to name overlap, but Medusa is distinct from MedusaLocker and other malware families.
  • High‑profile attack: Claimed responsibility for the Minneapolis Public Schools breach in March 2023, even releasing a video of stolen data.

Defensive Guidance from CISA, HHS, and FBI

Organizations are urged to:

  • Mitigate vulnerabilities: Patch operating systems, software, and firmware.
  • Segment networks: Limit lateral movement after compromise.
  • Restrict remote access: Block untrusted origins from accessing internal systems.
  • Monitor for suspicious activity: Watch for unusual file deletions, encryption attempts, or unauthorized access.

Expert in the Cloud Insight

Medusa’s expansion to over 500 victims underscores the industrialization of ransomware. By adopting a RaaS model and leveraging initial access brokers, Medusa has scaled its operations to target critical infrastructure at national levels. The lesson is clear: resilience requires layered defenses, from patch management to network segmentation, and proactive monitoring of ransomware tactics.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.