Hackread Storm-1175 Group Launches Rapid Medusa Ransomware Attacks
Article Content
- •Storm-1175 is executing high-speed Medusa ransomware attacks within 24 hours of breach.
- •Healthcare and education sectors in the UK, US, and Australia are primary targets.
- •Microsoft warns of zero-day vulnerabilities being exploited without prior disclosure.
Microsoft has identified a new cybercriminal group, Storm-1175, responsible for swift Medusa ransomware attacks targeting the healthcare and education sectors in the UK, US, and Australia. The group exploits zero-day vulnerabilities, allowing them to transition from initial access to data exfiltration and ransomware deployment within 24 hours. This alarming efficiency has raised significant concerns among cybersecurity experts. The attacks leverage security flaws that have not yet been disclosed, indicating a high level of sophistication in their methods. Microsoft has reported multiple incidents where organizations were compromised and held for ransom in a matter of hours. The exact number of affected organizations remains unspecified, but the scope of impact is considerable given the critical nature of the targeted sectors. As of now, there are no known patches or mitigations available for the vulnerabilities being exploited. The situation is ongoing, with Microsoft urging organizations to bolster their defenses against potential breaches.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Medusa and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026 The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication servers, and Linux management hosts. This shift allows Fire Ant to collect credentials, traffic, and…
Multiple Ransomware Attacks Target Diverse Industries in September 2026 In early September 2026, several ransomware groups executed attacks on various organizations, including Krybit's assault on Reignwood Park Thailand and Arab Maritime Petroleum Transport Company, Everest's attack on VIVOTEK, and Settra's targeting of Golden Neo Life. These incidents involved threats to leak sensitive…