The Cybersecurity and Infrastructure Security Agency (CISA) disclosed on Tuesday that the Medusa ransomware gang has compromised more than 500 critical infrastructure organizations in the United States since June 2021. The finding was released in a joint advisory with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI). The affected sectors include Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. Additional victims span the medical, education, legal, insurance, technology, and manufacturing industries.
The advisory updates a previous joint report from March 2025, which estimated that the Medusa operation had impacted over 300 critical infrastructure organizations. The new figure reflects a significant increase in the gang’s activity over the past year. CISA, HHS, and the FBI did not name any specific victims in the latest advisory, but they detailed recommended defensive measures for network administrators.
The federal agencies urged organizations to mitigate security vulnerabilities in operating systems, software, and firmware to block exploitation attempts. They also advised security teams to segment networks to prevent lateral movement after an initial compromise. Additionally, they recommended blocking access from untrusted origins to remote services on internal systems. These steps are intended to reduce the risk of both initial access and post-breach spread.
The Medusa ransomware operation first emerged in January 2021, but its activity did not escalate until 2023, when the gang launched a dedicated leak site called the Medusa Blog. The group began using stolen data as leverage to pressure victims into paying ransoms. The operation gained widespread media attention in March 2023 after claiming an attack on the Minneapolis Public Schools (MPS) district and publishing a video of the stolen data. That incident helped raise the profile of the group among cybersecurity watchers.
The name Medusa is used by multiple distinct cybercrime operations, including a Mirai-based botnet with ransomware capabilities and an Android malware-as-a-service (MaaS) track also known as TangleBot. Because of this naming overlap, reporting on Medusa ransomware has sometimes been ambiguous in the past. Security researchers have also frequently confused it with the separate MedusaLocker ransomware operation, though the two are not related. The advisory clarifies that the current threat concerns the group operating the Medusa Blog leak site.
The update comes as federal agencies continue to track ransomware trends across U.S. critical infrastructure. The joint advisory did not specify a ransom total or list any individual incidents tied to the 500-plus victim count. It also did not provide a timeline for when the latest breaches occurred beyond the overall June 2021 start date. The agencies emphasized that the advisory is meant to help network defenders harden their environments against active threats.
The source article also included a promotional note about an unrelated security report, but that content is not part of the federal advisory. No further details were provided about the Medusa gang’s tactics, tools, or payment demands. The advisory stands as a warning to U.S. organizations in critical sectors to review their security posture. The report is available for review on CISA’s website.






