Cryptelio

Hacks & Exploits

Medusa Ransomware Targets Over 500 U.S. Organizations Across Multiple Sectors

Cryptelio Editorial Published 9 Sep 2026 · 12:45 UTC

The Medusa ransomware group has significantly expanded its operations, affecting over 500 organizations across critical U.S. infrastructure sectors. The Cybersecurity and Infrastructure Security Agency (CISA) reported that the ransomware-as-a-service variant has targeted various industries, including healthcare, defense, manufacturing, government services, information technology, and financial services.

This increase marks a notable rise from the previous count of over 300 victims reported in March 2025. Medusa employs a double-extortion tactic, which involves encrypting systems and threatening to release stolen data unless a ransom is paid. The group has shifted to an affiliate model since early 2023, exploiting unpatched software vulnerabilities.

Ransom payments to initial access brokers can range from $100 to $1 million. The healthcare and public health sector has been particularly hard hit by these attacks. CISA recommends several mitigations, including timely software and firmware patching, network segmentation, and blocking untrusted access to remote services.

FAQ

What sectors are being targeted by Medusa ransomware?

Medusa ransomware has targeted various sectors including healthcare, defense, manufacturing, government services, information technology, and financial services.

How many organizations have been affected by Medusa ransomware?

Over 500 organizations across critical U.S. infrastructure sectors have been affected by Medusa ransomware.

What is the double-extortion tactic used by Medusa ransomware?

The double-extortion tactic involves encrypting systems and threatening to release stolen data unless a ransom is paid.

What are some recommended mitigations against Medusa ransomware?

CISA recommends timely software and firmware patching, network segmentation, and blocking untrusted access to remote services as mitigations against Medusa ransomware.

What is the range of ransom payments demanded by Medusa ransomware?

Ransom payments to initial access brokers can range from $100 to $1 million.

Read story →