Federal agencies including the FBI, CISA, and HHS warn that the Medusa ransomware operation has breached more than 500 U.S. critical infrastructure organizations since it first appeared in June 2021. The warning is based on an updated joint advisory that draws on FBI investigations conducted as late as April 2026 and follows an earlier advisory issued in March 2025.
Outlets report that the activity is tied to ransomware-as-a-service (RaaS) tactics, including recruiting initial-access brokers and affiliates through cybercriminal forums or marketplaces. Targeted sectors mentioned across reporting include healthcare, government, defense, manufacturing, IT, and financial organizations. Several sources note that the operation expands beyond earlier counts, with one report citing growth from more than 300 victims reported the previous year.
The differing emphasis across outlets centers on operational evolution and defender guidance. One outlet highlights that Medusa’s improved tactics, techniques, and procedures can make it harder for defenders to counter the threat. Others stress recommended mitigation steps such as patching and reducing vulnerabilities, segmenting networks to limit lateral movement, and restricting remote services and access from untrusted origins on internal systems.