CISA: Medusa ransomware hit over 500 critical infrastructure orgs

The Medusa Ransomware Gang Has Breached Over 500 Critical Infrastructure Organizations in the US

A shocking revelation from the Cybersecurity and Infrastructure Security Agency (CISA) has exposed a massive cyber threat to the country’s critical infrastructure. The agency revealed on Tuesday that the Medusa ransomware gang has compromised more than 500 organizations since June 2021, including those in healthcare, defense, manufacturing, and financial services.

This alarming number is an update to a previous joint report from March 2025, which estimated over 300 affected organizations. The three federal agencies – CISA, the Department of Health and Human Services (HHS), and the Federal Bureau of Investigation (FBI) – have issued a joint advisory urging network defenders to take immediate action to secure their networks against Medusa’s attacks.

Medusa is a type of ransomware that emerged in January 2021 but didn’t gain momentum until 2023, when it launched its blog leak site and began using stolen data as leverage to extort ransoms from victims. What makes Medusa particularly insidious is its business model, which involves recruiting initial access brokers (IABs) on cybercrime forums and marketplaces to obtain initial access to potential targets. These affiliates are offered payments ranging from $100 to $1 million, with the opportunity to work exclusively for Medusa.

The advisory highlights the importance of securing operating systems, software, and firmware against exploitation attempts by mitigating security vulnerabilities. It also recommends segmenting networks to block lateral movement after a compromise and blocking access from untrusted origins to remote services on internal systems. These measures are crucial in preventing the spread of the ransomware within an organization’s network.

The rise of Medusa is a stark reminder of the evolving threat landscape and the need for organizations to stay vigilant against emerging threats. The fact that over 500 critical infrastructure organizations have been affected by this gang since June 2021 raises serious concerns about the resilience of these systems and the ability of their operators to withstand cyber attacks.

In light of this revelation, it’s essential for security teams to review their defenses and take proactive measures to prevent similar breaches. By segmenting networks, blocking unauthorized access, and patching vulnerabilities, organizations can significantly reduce the risk of a Medusa attack. Additionally, staying informed about emerging threats and following best practices in cybersecurity can help mitigate the impact of such attacks.

As the threat landscape continues to evolve, it’s clear that no organization is immune to cyber attacks. However, by taking proactive steps to secure their networks and stay vigilant against emerging threats, organizations can reduce their risk and minimize the damage from a potential breach.


Source: Bleeping Computer — 2026-08-19