Storm-1175 Group Launches Rapid Medusa Ransomware Attacks

Storm-1175 Group Launches Rapid Medusa Ransomware Attacks

First seen 8 Apr 2026, 14:45 UTC Therecord.MediaHackreadwww.fortiguard.comFilestore.FortinetAcronis+1 85% similarity 63.9

Article Content

Browse articles
ThreatCluster

Microsoft has identified a new cybercriminal group, Storm-1175, responsible for swift Medusa ransomware attacks targeting the healthcare and education sectors in the UK, US, and Australia. The group exploits zero-day vulnerabilities, allowing them to transition from initial access to data exfiltration and ransomware deployment within 24 hours. This alarming efficiency has raised significant concerns among cybersecurity experts. The attacks leverage security flaws that have not yet been disclosed, indicating a high level of sophistication in their methods. Microsoft has reported multiple incidents where organizations were compromised and held for ransom in a matter of hours. The exact number of affected organizations remains unspecified, but the scope of impact is considerable given the critical nature of the targeted sectors. As of now, there are no known patches or mitigations available for the vulnerabilities being exploited. The situation is ongoing, with Microsoft urging organizations to bolster their defenses against potential breaches.

Key Points: • Storm-1175 is executing high-speed Medusa ransomware attacks within 24 hours of breach. • Healthcare and education sectors in the UK, US, and Australia are primary targets. • Microsoft warns of zero-day vulnerabilities being exploited without prior disclosure.

ThreatCluster AI

Timeline

2026-04-06
Microsoft reports on Medusa ransomware group effectiveness.
2026-04-08
Hackread publishes details on Storm-1175 attacks.

Community

Browse all →

Tracked Entities in This Story