CISA: Medusa ransomware hit over 500 critical infrastructure orgs

A Devastating Wave of Ransomware Attacks Hits Over 500 Critical Infrastructure Organizations

The Cybersecurity and Infrastructure Security Agency (CISA) has revealed that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. This staggering number was disclosed in a joint advisory issued by CISA, the Federal Bureau of Investigation (FBI), and the Department of Health and Human Services (HHS). The affected sectors include Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services.

Medusa ransomware is a type of malware that uses an affiliate model to gain access to potential victims. The attackers typically recruit initial access brokers (IABs) in cybercriminal forums and marketplaces to obtain initial access to the target systems. These IABs are then offered payments ranging from $100 USD to $1 million USD for their services, with the opportunity to work exclusively for Medusa. Once inside, the attackers use stolen data as leverage to pressure victims into paying ransoms.

The Medusa operation emerged in 2023 when it launched a leak site and started using stolen data to pressure victims into paying ransoms. Since then, the gang has been linked to several high-profile attacks, including one on the Minneapolis Public Schools (MPS) district. The attack was notable for the attackers’ decision to share a video of the stolen data, drawing media attention to their operation.

The joint advisory from CISA and its partners warns that security teams need to take immediate action to protect themselves against Medusa’s attacks. This includes mitigating security vulnerabilities to prevent exploitation attempts, segmenting networks to block lateral movement after compromise, and blocking access from untrusted origins to remote services on internal systems.

What makes the situation even more alarming is that once attackers have valid credentials, only 37% of their actions are blocked. This highlights the importance of having robust cybersecurity measures in place, especially for critical infrastructure organizations. The Blue Report 2026 notes that overall prevention scores can hide what happens after initial access, emphasizing the need for continuous monitoring and improvement.

In light of these findings, it is essential for security teams to review their defenses and ensure they are equipped to handle ransomware attacks like Medusa. This includes implementing robust security protocols, conducting regular vulnerability assessments, and staying up-to-date with the latest threat intelligence. By taking proactive steps, organizations can reduce their risk exposure and minimize the impact of such devastating attacks.

As a practical takeaway, security teams should focus on ensuring that their networks are secure against exploitation attempts by regularly patching software vulnerabilities, implementing robust access controls, and segmenting networks to prevent lateral movement. Additionally, staying informed about the latest threat intelligence and best practices in cybersecurity will help organizations stay ahead of emerging threats like Medusa ransomware. By being vigilant and proactive, security teams can better protect their organizations against these types of attacks and maintain trust with their stakeholders.


Source: Bleeping Computer — 2026-08-19