Utopia Tech
Healthcare4 min read

Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs

CISA, the Department of Health and Human Services (HHS), and the Federal Bureau of Investigation (FBI) have issued an updated cybersecurity advisory about the Medusa ransomware-as-a-service (RaaS) group, which has now claimed more than 500 critical infrastructure victims. When the cybersecurity advisory was first issued in March 2025, the authorizing agencies determined that Me

UT

Utopia Tech

August 20, 2026 · 4 min read

Share

CISA, the Department of Health and Human Services (HHS), and the Federal Bureau of Investigation (FBI) have issued an updated cybersecurity advisory about the Medusa ransomware-as-a-service (RaaS) group, which has now claimed more than 500 critical infrastructure victims. When the cybersecurity advisory was first issued in March 2025, the authorizing agencies determined that Medusa had conducted more than 300 attacks on critical infrastructure entities between 2021 and February 2025.

The Medusa ransomware operation emerged in June 2021 and initially operated as a closed ransomware group, with the developers conducting all aspects of the operation, including development, ransomware campaigns, and ransom negotiations. In early 2023, Medusa morphed into a RaaS operation, using affiliates to conduct attacks for a percentage of the ransom payments.

The group also launched a data leak site in 2023 and adopted double extortion tactics, issuing threats to publish stolen data to pressure victims into paying to prevent data leaks as well as to obtain the keys to decrypt data. Since the transformation into a RaaS group, attacks have increased substantially, with the developers and the group’s affiliates conducting attacks.

In a little over a year, the group has claimed more than 200 victims in critical infrastructure sectors, compared to 300 in the previous four years. Affiliates are given various levels of control based on their experience and profitability, with newer and less experienced affiliates having lower levels of trust. For instance, the developers retain control of important aspects of campaigns such as ransom negotiations for newer and less experienced affiliates.

The developers recruit initial access brokers (IABs) on cybercriminal forums to provide access to victims’ networks, typically paying between $100 and $1 million to the IAB for access. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy While some RaaS groups have a policy of not attacking healthcare organizations, that is certainly not true of Medusa, which has frequently attacked the healthcare and public health (HPH) sector.

While the group is largely believed to operate opportunistically, conducting attacks by focusing on organizations with unpatched, remotely exploitable software vulnerabilities, the high percentage of victims in the HPH sector could indicate targeting of the sector. Medusa attacks typically start with phishing or the exploitation of unpatched vulnerabilities.

The group incorporates exploits for recently announced vulnerabilities into it arsenal. For instance, the CVE-2026-1731 BeyondTrust vulnerability started to be exploited soon after it was announced in February 2026, and the CVE-2025-10035 Fortra GoAnywhere vulnerability was also rapidly exploited. The authoring agencies have observed the group incorporating new exploits within 24 hours of a vulnerability being announced and, in some cases, has started exploiting vulnerabilities in the week prior to an announcement.

No evidence has been found to indicate that the group develops its own exploits; rather, the group is believed to obtain exploits from unknown sources, potentially IABs, exploiting them before victims have the time to patch. Medusa actors use living-of-the-land techniques, hiding their malicious activities by using legitimate tools to support credential access, data exfiltration, and ransomware deployment.

Remote monitoring and management software and remote access services such as Remote Desktop Protocol are also used. The key actions that HPH sector organizations should take to prevent attacks are to mitigate known vulnerabilities rapidly, ensuring all software, firmware, and operating systems are kept patched and up to date. Networks should be segmented to restrict lateral movement within the network, and network traffic should be filtered to prevent unknown or untrusted origins from accessing remote services on internal systems.

March 13, 2025: Critical Infrastructure Entities Warned About Medusa Ransomware as Victim Count Hits 300 A warning has been issued about the Medusa ransomware-as-a-service (RaaS) group, which has now claimed more than 300 victims in critical infrastructure sectors including healthcare, education, and manufacturing. The group has been active since June 2021 when it started as a closed group, before adopting the RaaS model, where affiliates are recruited to conduct attacks for a percentage of any ransom payments they generate.

Around two years after the group formed, Medusa launched a data leak site where victims are named and stolen data is published if the ransom is not paid. This double extortion method, where the ransom must be paid to obtain the decryption keys and prevent the publication of stolen data, is common among RaaS groups, although in the case of Medusa, its core members have retained control of ransom negotiations.

According to the joint cybersecurity alert from the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Multi-State Information Sharing and Analysis Center (MS-ISAC), the Medusa developers recruit initial access brokers (IABs) on cybercriminal forums and marketplaces and incentivize them to work solely with Medusa.

The authoring agencies have observed affiliates using phishing to obtain credentials to access victims’ networks, as well as exploiting unpatched software vulnerabilities, including last year’s ScreenConnect vulnerability CVE-2024-1709 and the Fortinet EMS SQL injection vulnerability CVE-2023-48788.

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content