Medusa Ransomware Hits 500+ Critical Infrastructure Victims

Medusa Ransomware Victim Count Surpasses 500, US Agencies Warn

HIGH
August 21, 2026
August 24, 2026
5m read
RansomwareThreat ActorCyberattack

Related Entities(initial)

Other

Medusa gaze.exeGrandview Family MedicineOrganonInsightin HealthHeartland Health Center

Full Report(when first published)

Executive Summary

A joint cybersecurity advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Department of Health and Human Services (HHS) warns that the Medusa ransomware operation has impacted over 500 critical infrastructure organizations worldwide as of April 2026. This marks a significant escalation from the 300 victims reported in March 2025. The group's transition to a Ransomware-as-a-Service (RaaS) model in early 2023 has dramatically increased its operational tempo, with a notable focus on the healthcare sector. Organizations are urged to review their defenses against this opportunistic and rapidly evolving threat.

Threat Overview

First observed in June 2021, the Medusa operation evolved from a private group to a public RaaS platform in early 2023. This strategic shift has allowed the group to scale its attacks by recruiting affiliates and initial access brokers (IABs) from underground forums, paying substantial fees for network access. The group operates opportunistically, targeting organizations with known, unpatched vulnerabilities rather than specific industries. However, a pattern has emerged showing frequent attacks against the Healthcare and Public Health (HPH), education, legal, insurance, technology, and manufacturing sectors.

Medusa employs a double-extortion model. After infiltrating a network and exfiltrating sensitive data, the actors deploy the ransomware to encrypt files. They then demand a ransom payment, threatening to publish the stolen data on their public leak site if the victim does not comply. The group has demonstrated an aggressive capability to weaponize newly disclosed vulnerabilities, sometimes within 24 hours of public announcement.

Technical Analysis

Medusa's affiliates leverage a variety of tactics, techniques, and procedures (TTPs) to achieve their objectives. Initial access is often gained by exploiting vulnerabilities in public-facing applications or through credentials purchased from IABs.

Once inside a network, the threat actors use legitimate remote monitoring and management (RMM) software and built-in tools like PowerShell to blend in with normal administrative activity and evade detection. This "living-off-the-land" approach makes it difficult for security tools to distinguish malicious actions from benign ones.

After conducting reconnaissance and moving laterally to gain control of the environment, the final payload, often a file named gaze.exe, is deployed to encrypt files across the network. The group is known for its thoroughness in disabling security and backup solutions to ensure maximum impact and hinder recovery efforts.

MITRE ATT&CK Techniques Observed:

Impact Assessment

The impact of a Medusa ransomware attack is severe, extending beyond financial loss. For critical infrastructure, particularly healthcare, an attack can disrupt essential services, leading to canceled appointments, delayed medical procedures, and, in the worst cases, risks to patient safety. The double-extortion tactic adds the significant risk of a data breach, exposing sensitive patient, customer, or corporate data. This can result in regulatory fines, legal action, and long-term reputational damage. Recovery is often complex and costly, requiring extensive forensic analysis, system restoration, and security posture improvements.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were provided in the source articles.

Cyber Observables — Hunting Hints

Security teams may want to hunt for the following patterns that could indicate Medusa-related activity:

Type
Process Name
Value
gaze.exe
Description
A known filename for the Medusa ransomware payload.
Type
Command Line Pattern
Value
powershell.exe -enc
Description
Monitor for encoded PowerShell commands, a common obfuscation technique.
Type
Network Traffic Pattern
Value
Unusual large data uploads to unknown destinations
Description
Could indicate data exfiltration prior to encryption.
Type
Log Source
Value
EDR / Endpoint Logs
Description
Monitor for the installation and execution of new RMM software not on an approved list.
Type
Event ID
Value
4688 (Windows)
Description
Look for suspicious process creation, especially a known RMM tool spawning cmd.exe or powershell.exe.

Detection & Response

  • EDR and SIEM: Implement and tune Endpoint Detection and Response (EDR) and Security Information and Event Management (SIEM) solutions to detect anomalous behavior. Create rules to alert on the execution of unauthorized RMM software, suspicious PowerShell scripts, and commands used to disable security controls or delete backups (e.g., vssadmin.exe delete shadows).
  • Network Monitoring: Utilize network traffic analysis (D3-NTA) to baseline normal data flows and alert on significant deviations, especially large outbound transfers to unfamiliar IP addresses or cloud storage services.
  • Log Analysis: Actively review authentication logs for signs of brute-force attacks or credential abuse. Centralize logs from critical systems, including domain controllers and file servers, to facilitate timely investigation.

Mitigation

  • Patch Management: Prioritize and accelerate the patching of vulnerabilities, especially those in internet-facing systems. Medusa is known to exploit new CVEs quickly. (D3-SU: Software Update)
  • Access Control: Enforce the principle of least privilege. Implement robust access controls and mandate the use of Multi-factor Authentication (MFA) for all remote access, privileged accounts, and critical systems. (D3-MFA)
  • Network Segmentation: Segment networks to prevent lateral movement. Isolate critical systems and OT environments from the corporate IT network. Restrict access between network segments to only what is necessary for business operations. (D3-NI: Network Isolation)
  • Backups: Maintain offline, encrypted, and tested backups of critical data. Ensure backups are immutable and cannot be deleted or altered by an attacker who gains administrative privileges.

Timeline of Events

1
June 1, 2021
Medusa ransomware operation is first identified.
2
January 1, 2023
Medusa transitions from a closed group to a Ransomware-as-a-Service (RaaS) model.
3
March 1, 2025
Previous government advisories report Medusa has compromised 300 victims.
4
April 1, 2026
The victim count attributed to Medusa surpasses 500 critical infrastructure organizations.
5
August 21, 2026
This article was published

Article Updates

August 24, 2026

Updated advisory confirms over 500 Medusa victims, detailing new TTPs including phishing, specific exploited vendors (ScreenConnect, Fortinet), and pressure tactics.

MITRE ATT&CK Mitigations

Implement a rigorous patch management program to remediate vulnerabilities in public-facing applications that Medusa actors exploit for initial access.

Mapped D3FEND Techniques:

Enforce MFA on all remote access points, administrative accounts, and critical system logins to prevent unauthorized access even if credentials are compromised.

Mapped D3FEND Techniques:

Segment the network to contain the spread of a ransomware attack and protect critical assets. Isolate sensitive systems to limit an attacker's lateral movement.

Mapped D3FEND Techniques:

Train users to recognize and report phishing attempts, which are a common vector for ransomware groups to gain initial access.

Timeline of Events

1
June 1, 2021

Medusa ransomware operation is first identified.

2
January 1, 2023

Medusa transitions from a closed group to a Ransomware-as-a-Service (RaaS) model.

3
March 1, 2025

Previous government advisories report Medusa has compromised 300 victims.

4
April 1, 2026

The victim count attributed to Medusa surpasses 500 critical infrastructure organizations.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Ransomware-as-a-ServiceRaaSDouble ExtortionInitial Access BrokerHealthcare CybersecurityCritical Infrastructure

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.