"As of April 2026, Medusa actors have impacted more than 500 victims across multiple critical infrastructure sectors, including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services," the Cybersecurity and Infrastructure Security Agency (CISA) said in a joint advisory Tuesday with the Federal Bureau of Investigation (FBI) and the Department of Health and Human Services (HHS).
Scope: more than 500 critical infrastructure organizations since June 2021
The joint advisory updates a March 2025 report that estimated Medusa had impacted "over 300 critical infrastructure organizations." CISA, the FBI and HHS now say the operation has breached more than 500 U.S. critical infrastructure victims since June 2021. The advisory lists affected critical infrastructure sectors explicitly: Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. It also notes additional victims in the medical, education, legal, insurance, technology, and manufacturing industries.
Medusa’s operational evolution: closed variant to RaaS and affiliate model
According to the advisory, the Medusa operation first surfaced in January 2021 but intensified in 2023. The group launched the "Medusa Blog" leak site that year and began using stolen data publicly to pressure victims for ransom. The advisory says Medusa initially appeared as a closed ransomware variant but later "evolved into a Ransomware-as-a-service (RaaS) operation and adopted an affiliate model."
Medusa developers reportedly recruit initial access brokers (IABs) in cybercriminal forums and marketplaces to procure entry to victim networks. The advisory states potential payments to affiliates range "between $100 USD and $1 million USD" and that affiliates may be offered the opportunity to work exclusively for Medusa.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageTactics and confusion: brokers, leak sites, and competing names
The agencies explain that Medusa actors have used stolen data publication as leverage and that the group's recruitment of IABs supports wider compromise campaigns. The advisory also warns of naming confusion: "Medusa is a commonly used name among malware families and cybercrime operations," the agencies say, citing other uses of the Medusa name — including a 2020 Android malware-as-a-service (also known as TangleBot) and a Mirai-based botnet with ransomware capabilities. The report cautions that some reporting has conflated Medusa with the different MedusaLocker operation.
The advisory further highlights a concrete incident that drew media attention: in March 2023, the Medusa operation claimed an attack on Minneapolis Public Schools and published a video of stolen data.
Defensive measures the agencies recommended
CISA, the FBI and HHS recommended a set of concrete steps for network defenders. They advised mitigating security vulnerabilities to protect operating systems, software, and firmware from exploitation attempts; segmenting networks to impede lateral movement after compromise; and blocking access from untrusted origins to remote services on internal systems. These recommendations are presented as ways to reduce the attack surface and the operational impact once adversaries gain a foothold.
What this means for technologists, policymakers, and healthcare organizations
- Technologists and security teams: The advisory underscores the need to prioritize vulnerability management, firmware and software hardening, and network segmentation to limit lateral movement and reduce exposure to affiliates and initial access brokers.
- Policymakers and regulators: The scale of the advisory — an increase from "over 300" to "more than 500" victims — frames a case for evaluating whether existing reporting, oversight, or sector-specific resilience measures are sufficient for ransomware that leverages affiliate ecosystems.
- Healthcare and public health organizations: Named directly among impacted sectors, these organizations are urged to follow the agencies' mitigation steps to protect patient-care systems and sensitive data from both encryption and public data-leak pressure tactics.
Two additional observations in the advisory provide context. First, the record of Medusa’s recruiting and public leak tactics illustrates how ransomware operators monetize stolen data beyond pure encryption. Second, the advisory quotes an analytic point about defenses: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." That assessment — echoed by a separate Blue Report 2026 metric that measures defenses across 338 million simulations in customer production environments — highlights the operational challenge defenders face when attackers convert initial access into broader compromise.
For defenders and organizations that intersect with the named sectors, the advisory offers a clear checklist: patch and harden systems, segment networks, and block untrusted remote access. For the agencies that published the advisory, the immediate next step is providing that guidance while monitoring the continuing evolution of a RaaS operation that has moved from a niche ransomware family into a broader affiliate economy.




