Medusa Ransomware Group Targets Over 500 U.S. Critical Infrastructure Organizations

Photo: BleepingComputer
Quick answer
The Medusa ransomware group, active since 2021, has targeted over 500 U.S. critical infrastructure organizations, including healthcare and defense sectors.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the FBI and the Department of Health and Human Services, has issued an updated advisory on the Medusa ransomware group. According to the report, this cybercriminal group has attacked over 500 critical infrastructure organizations since June 2021, including companies in healthcare, defense, government, IT, and financial services.
Medusa began operations in January 2021, but its activity surged in 2023 following the launch of the Medusa Blog platform, where victim data is published. This allowed the threat actors to increase pressure on affected organizations by demanding ransoms to prevent the disclosure of sensitive information. The group operates under a Ransomware-as-a-Service (RaaS) model, recruiting affiliates through cybercrime forums and offering rewards ranging from $100 to $1 million for successful attacks.
Experts note that the name Medusa is often associated with confusion, as it is used by different cybercriminal groups, including the Mirai-based botnet and Android malware. However, this case refers to a distinct operation separate from MedusaLocker. To mitigate risks, specialists recommend patching software vulnerabilities, segmenting networks, and restricting access to internal systems from untrusted sources.
Common questions
- What is the Medusa ransomware group?
- Medusa is a cybercriminal group specializing in ransomware attacks. It began operations in 2021 and has since expanded its activities significantly.
- Which industries have been affected by Medusa attacks?
- Primary victims include healthcare, defense, government, IT, financial services, as well as educational and legal institutions.
- How can organizations protect themselves from Medusa attacks?
- Recommendations include patching software vulnerabilities, segmenting networks to prevent lateral movement, and restricting access to remote services from untrusted sources.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml