Skip to content
Medusa ransomware gang hits 500 critical infrastructure organisations, US agencies warn

Medusa ransomware gang hits 500 critical infrastructure organisations, US agencies warn

Computing August 19, 2026

The Medusa RaaS gang had adapted its tactics and compromised more than 500 organisations providing critical infrastructure in the US.

An updated advisory issued yesterday in the US by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI and Health and Human Services Department (HHS) says that the Medusa ransomware-as-a-service (RaaS) gang has breached more than 500 critical infrastructure organisations in the US since June 2021.

It said: "As of April 2026, Medusa actors have impacted more than 500 victims across multiple critical infrastructure sectors, including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services."

"Other victims include organizations in the medical, education, legal, insurance, technology, and manufacturing industries."

The advisory warns that the group has adapted its tactics since it last warned them in March 2025. It is now relying on access brokers, with those working exclusively for the gang picking up payments of up to $1 million.

James Neilson, SVP of Global at OPSWAT commented:

Medusa ransomware group’s modus operandi is to seek privileged access and then move laterally to find valuable systems on which to deploy the ransomware. IT systems, internet connectivity, and transient devices remain major attack surfaces for ICS/OT infrastructure, and Medusa ransomware looks to exploit these.”

The Medusa group was first identified in 2021. James Neilson continues:

“One of the major factors in why Medusa ransomware has been so successful in breaching critical infrastructure organisations is that there’s a lack of understanding among security teams regarding the impact of IT threats on OT environments.

“IT security controls are often directly applied to OT systems, which creates a false sense of security and causes disruptive false positives. Many organisations neglect to secure data that moves in and out of their OT networks and to implement security practices tailored to ICS/OT systems.”

Security teams are therefore advised to segment networks to block lateral movement after compromise and to implement zero-trust policies for remote connections.

Extracted Entities

Attack Types (1)

Companies (1)

MITRE ATT&CK (1)

Ransomware Groups (1)