A joint cybersecurity advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Department of Health and Human Services (HHS) warns that the Medusa ransomware operation has impacted over 500 critical infrastructure organizations worldwide as of April 2026. This marks a significant escalation from the 300 victims reported in March 2025. The group's transition to a Ransomware-as-a-Service (RaaS) model in early 2023 has dramatically increased its operational tempo, with a notable focus on the healthcare sector. Organizations are urged to review their defenses against this opportunistic and rapidly evolving threat.
First observed in June 2021, the Medusa operation evolved from a private group to a public RaaS platform in early 2023. This strategic shift has allowed the group to scale its attacks by recruiting affiliates and initial access brokers (IABs) from underground forums, paying substantial fees for network access. The group operates opportunistically, targeting organizations with known, unpatched vulnerabilities rather than specific industries. However, a pattern has emerged showing frequent attacks against the Healthcare and Public Health (HPH), education, legal, insurance, technology, and manufacturing sectors.
Medusa employs a double-extortion model. After infiltrating a network and exfiltrating sensitive data, the actors deploy the ransomware to encrypt files. They then demand a ransom payment, threatening to publish the stolen data on their public leak site if the victim does not comply. The group has demonstrated an aggressive capability to weaponize newly disclosed vulnerabilities, sometimes within 24 hours of public announcement.
Medusa's affiliates leverage a variety of tactics, techniques, and procedures (TTPs) to achieve their objectives. Initial access is often gained by exploiting vulnerabilities in public-facing applications or through credentials purchased from IABs.
Once inside a network, the threat actors use legitimate remote monitoring and management (RMM) software and built-in tools like PowerShell to blend in with normal administrative activity and evade detection. This "living-off-the-land" approach makes it difficult for security tools to distinguish malicious actions from benign ones.
After conducting reconnaissance and moving laterally to gain control of the environment, the final payload, often a file named gaze.exe, is deployed to encrypt files across the network. The group is known for its thoroughness in disabling security and backup solutions to ensure maximum impact and hinder recovery efforts.
The impact of a Medusa ransomware attack is severe, extending beyond financial loss. For critical infrastructure, particularly healthcare, an attack can disrupt essential services, leading to canceled appointments, delayed medical procedures, and, in the worst cases, risks to patient safety. The double-extortion tactic adds the significant risk of a data breach, exposing sensitive patient, customer, or corporate data. This can result in regulatory fines, legal action, and long-term reputational damage. Recovery is often complex and costly, requiring extensive forensic analysis, system restoration, and security posture improvements.
No specific Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were provided in the source articles.
Security teams may want to hunt for the following patterns that could indicate Medusa-related activity:
gaze.exepowershell.exe -enccmd.exe or powershell.exe.vssadmin.exe delete shadows).Updated advisory confirms over 500 Medusa victims, detailing new TTPs including phishing, specific exploited vendors (ScreenConnect, Fortinet), and pressure tactics.
Implement a rigorous patch management program to remediate vulnerabilities in public-facing applications that Medusa actors exploit for initial access.
Mapped D3FEND Techniques:
Enforce MFA on all remote access points, administrative accounts, and critical system logins to prevent unauthorized access even if credentials are compromised.
Mapped D3FEND Techniques:
Segment the network to contain the spread of a ransomware attack and protect critical assets. Isolate sensitive systems to limit an attacker's lateral movement.
Train users to recognize and report phishing attempts, which are a common vector for ransomware groups to gain initial access.
Medusa ransomware operation is first identified.
Medusa transitions from a closed group to a Ransomware-as-a-Service (RaaS) model.
Previous government advisories report Medusa has compromised 300 victims.
The victim count attributed to Medusa surpasses 500 critical infrastructure organizations.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.