snake
Image: Unsplash/Photomosh

More than 200 victims of Medusa ransomware identified over the last year, CISA says

Federal cybersecurity agencies warned on Tuesday that troves of new victims of the Medusa ransomware gang have been identified over the last year.

The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.

The group caused widespread outrage in April when it shut down the University of Mississippi Medical Center — Mississippi’s only children's hospital, only Level I trauma center, only Level IV neonatal intensive care unit and home to the state’s only organ transplant program.

Tuesday’s advisory warned that the group has focused its efforts on the healthcare sector and has become adept at exploiting “newly announced exploits within 24 hours.” 

The ransomware gang has “been observed to use exploits up to a week before public vulnerability disclosure,” the agencies added, citing a recent report from Microsoft about the trend of Medusa actors targeting victims using software that has not been updated to include new patches. 

“However, there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, preferring instead to obtain advanced access to exploits from unknown sources or to quickly leverage newly announced exploits before potential victims can mitigate vulnerabilities through patching,” the advisory said. 

Medusa was originally a closed ransomware gang but transitioned to an affiliate model in 2023, selling its ransomware to hackers who are granted varying levels of access based on their experience and earnings. 

“For newer or less experienced affiliates, important operations such as ransom negotiation may be centrally controlled by the developers,” the agencies explained. 

Medusa actors typically offer lower ransoms to victims if they pay quickly but they often do research on companies before attacks, basing ransom amounts on publicly announced revenue. 

While Medusa does remove victim information from its site after a ransom is paid, the agencies noted that there is no way to verify whether it is truly deleted. 

Victims are often given an offer of $10,000 to add one extra day to the deadline before stolen data is released to the public. 

The advisory references one incident seen by FBI investigators where a victim was “contacted by a separate Medusa actor who claimed the negotiator had stolen the ransom amount already paid and requested half of the payment be made again to provide the ‘true decryptor’ — potentially indicating a triple-extortion scheme, or operational dysfunction and a lack of cohesion among ransomware group.”

Medusa recruits members on cybercriminal forums and offers up to $1 million to initial access brokers who want to work exclusively for the group. 

CISA and the FBI included technical advice victims can turn to when investigating Medusa attacks, noting that the hackers use several credential stealing tools before turning to legitimate remote monitoring software to evade detection. 

The FBI said Medusa actors used remote access software AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp and Splashtop. 

Medusa has not added any new victims to its leak site since April, leading several experts to believe the attack on the University of Mississippi Medical Center drew significant, unwanted law enforcement attention to the group. The group, which emerged in 2021, has repeatedly shown a willingness to target healthcare facilities as well as international and U.S. municipal governments.

The advisory’s focus on Medusa’s ability to quickly exploit zero-days drew the most interest from researchers, who warned that several groups are increasingly jumping on new vulnerabilities before defenders have a chance to install patches.

“We’re seeing a clear escalation in the speed and coordination of operations… particularly in how quickly newly disclosed and even zero-day vulnerabilities are being operationalized,” said SafeBreach’s Adrian Culley.

Culley added that the hackers tied to Medusa are “moving from initial access to data exfiltration in hours, not days.”

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.