Skip to content

medusa

Inactive

25 tracked victims · First seen Jan 11, 2023 · Last seen Feb 13, 2026

About

Aggregated threat-intel description

Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.

Sectors: Business Services, Healthcare, Manufacturing · Countries: US, GB, CA

Recent victims

View all →
VictimSectorCountryPostedStatus
LicindiaOtherINSep 2, 2026
LawterManufacturingUSSep 1, 2026
JgseeNot FoundTHAug 27, 2026
ServifruitAgriculture and Food ProductionMXAug 27, 2026
Hungry LionRetail & E-CommerceGHAug 27, 2026
QualisteelManufacturingAug 27, 2026
HealthHealthcareAUAug 27, 2026
Twal Family IT LabTechnologyAug 16, 2026
All Parts Dry CleaningRetail & E-CommerceGBAug 16, 2026
Idex GroupTechnologyDEAug 16, 2026
Bija IndustrieManufacturingFRAug 16, 2026
ThecourierguyTransportationZAAug 16, 2026
ForcesNot FoundCAJul 7, 2026
EstrelaConsumer ServicesBRJul 1, 2026
KarneslegalBusiness ServicesJul 1, 2026
Sgs GmbhBusiness ServicesDEJul 1, 2026
DadolightingManufacturingJul 1, 2026
T OnlineCharityDEMay 11, 2026
FunkeScheidManufacturingDEJul 1, 2026
Mairie Thiverval GrignonAcademiaFRJul 1, 2026
DolradNot FoundAEJul 1, 2026
BdHealthcareCHJul 1, 2026
Penticton and District Society for Community LivingHealthcareCAJul 1, 2026
Balloons EverywhereConsumer ServicesUSFeb 14, 2026
South Hays Fire DepartmentPublic SectorUSFeb 14, 2026

All ransomware groups · Dark web intelligence