The Medusa ransomware operation has now compromised more than 500 organizations across critical infrastructure sectors, prompting an updated joint warning from US federal agencies that its evolving tactics are making attacks harder to stop[5][12][13].
In a refreshed #StopRansomware advisory, CISA, the FBI and the Department of Health and Human Services report that Medusa’s developers and affiliates have moved from impacting roughly 300 known victims in early 2025 to more than 500 by April 2026, with healthcare, defense, manufacturing, government services, IT and financial services among the hardest hit[1][5][11][12]. Medusa, first identified in June 2021 and run as a ransomware-as-a-service (RaaS) program, enables multiple affiliate crews to rent the malware and infrastructure, splitting profits from ransom payments[1][9][14].
The advisory and supporting research describe Medusa actors leaning on familiar but effective techniques: credential-harvesting phishing campaigns, exploitation of unpatched internet-facing systems, and abuse of remote administration tools to gain initial access[1][2][3]. Technical analysis from ManageEngine notes that Medusa affiliates have exploited an authentication-bypass flaw in ConnectWise ScreenConnect (CVE-2024-1709) and a SQL injection bug in Fortinet’s Endpoint Management Server (CVE-2023-48788), both used to pivot into high-value networks when left unpatched[7]. Once inside, operators deploy tooling such as network scanners and credential-dumping utilities, enumerate domain admin accounts, exfiltrate sensitive data and finally encrypt systems to maximize leverage on victims[1][7][14].
US agencies and independent threat profiles describe Medusa as a “big-game hunting” outfit that carefully selects targets likely to pay, including hospitals and public health entities where downtime can directly impact patient care[5][12][13]. A threat actor profile from Huntress highlights that Medusa maintains a leak site to publish stolen data from victims who refuse to meet ransom demands, aligning with the double-extortion model that has become standard across the RaaS ecosystem[3][14]. This combination of data theft, operational disruption and public shaming raises the stakes for victim organizations and complicates incident response, especially in regulated sectors where breaches trigger mandatory disclosure and potential fines[5][9][14].
Defenders also face challenges from Medusa’s operational maturity. The joint advisory warns that affiliates actively recruit initial access brokers with offers ranging from tens of thousands to seven figures for footholds into desirable networks, accelerating campaigns by tapping into a gray market for compromised credentials and VPN endpoints[1][7][14]. Security walkthroughs of the advisory by researchers at Valtik Studios underscore how Medusa playbooks include rapid privilege escalation, shadow copy deletion, event log clearing and the use of tools like Rclone and FileZilla for bulk data theft, all designed to stay just ahead of routine monitoring in many environments[8][14].
To blunt this surge, the government guidance urges organizations to prioritize patching of internet-facing services, especially remote access tools and security management platforms, and to enforce strong segmentation so ransomware operators cannot easily move from user networks into critical operational systems[1][2][5]. Agencies recommend filtering or blocking untrusted network traffic to remote services, enforcing multifactor authentication, tightening domain admin use, and deploying robust detection rules for behaviors such as creation of unexpected privileged accounts, shadow copy deletion and encoded PowerShell commands[1][2][8]. The advisory further calls on victims to report Medusa incidents promptly to federal authorities, both to receive assistance and to help refine collective intelligence on the group’s tools, tactics and procedures as they continue to evolve[1][2][5].
References
- #StopRansomware: Medusa Ransomware
- CISA and Partners Release Cybersecurity Advisory on …
- Medusa ransomware slams critical infrastructure …
- Medusa ransomware gang has hit over 500 organizations, CISA warns
- Medusa Ransomware: IOCs, MITRE TTPs & Detection
- CISA Advisory Walkthrough + The Defensive Baseline – Valtik Studios
- Medusa Ransomware Group: A Rising Threat in 2025
- aa25-071a-stopransomware-medusa-ransomware. …
- CISA Warns Medusa Ransomware Hit 500+ Organizations …
- Radoslav Krehlik’s Post
- Medusa Threat Actor Profile: TTPs, IOCs & Attacks | Huntress
