Medusa passes five hundred organisations
A joint advisory puts the count above 500 as of April, against 300 in March last year — and names what the affiliates are paid.
SeverityHigh
2 minThreat Intelligence
CISA, the FBI and HHS issued an updated joint advisory on 19 August recording more than 500 critical infrastructure organisations breached by Medusa as of April 2026. The comparable figure in the March 2025 advisory was over 300.
The named sectors are healthcare and public health, the defence industrial base, critical manufacturing, government services and facilities, information technology and financial services, with medical, education, legal, insurance and technology organisations also affected. Medusa has been active since January 2021 and escalated from 2023.
The number that describes the business
Medusa runs as ransomware-as-a-service and recruits affiliates, and the advisory records what it pays initial access brokers: between $100 and $1 million per access. That range is the whole economics of the model in one line — the low end makes opportunistic credential theft worth someone's afternoon, the high end makes a deliberate campaign against a named target worth funding.
Extortion runs through the Medusa Blog leak site, so the leverage is publication rather than encryption alone.
The recommendations are unchanged and unglamorous: patch operating systems, software and firmware; segment networks to limit lateral movement; block untrusted access to remote internal services. Nothing in the advisory suggests a novel technique — the growth from 300 to 500 came from the same methods applied to more targets.
Retold from BleepingComputer. This is a summary in our own words; follow the link for the original reporting.