Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

Medusa ransomware breaches more than 500 organisations

Medusa ransomware operators have compromised more than 500 organisations across critical infrastructure sectors, prompting US cyber authorities to warn that the group is exploiting vulnerabilities faster and using increasingly aggressive methods to penetrate networks and extort victims. An updated joint cybersecurity advisory from the Federal Bureau of Investigation, Cybersecurity and…

In April 2026, the FBI, Cybersecurity and Infrastructure Security Agency, and Department of Health and Human Services warned that the Medusa ransomware group had compromised over 500 organisations across critical infrastructure sectors. This marked a significant increase from 300 victims identified in February 2025, reflecting the expansion of Medusa's ransomware-as-a-service operations since its emergence in June 2021.

Industries targeted by the group include healthcare, defence industrial base, critical manufacturing, government services and facilities, information technology, and financial services. Healthcare has become particularly vulnerable due to the potential impact on clinical services and the leverage provided by stolen medical data.

Medusa's rapid attacks, exploiting newly disclosed security flaws within 24 hours and sometimes up to a week before public disclosure, have made it challenging for defenders to patch vulnerabilities in time. The group, which began as a closed operation, now offers ransomware infrastructure to affiliates who handle parts of the criminal enterprise, including ransom negotiations.

Initial access brokers have played a crucial role, offering payments ranging from $100 to $1 million for compromised organisations. Attackers use a variety of remote-access products and credential-stealing tools to blend malicious activity with routine system management. Medusa's double extortion tactics, which involve stealing data before encryption and threatening to publish or sell it, have been observed.

Victims have been offered an additional day to pay for an undetected decryption before publication. In one instance, a victim that had already paid was contacted by another Medusa actor demanding a second payment for the genuine decryptor, raising concerns about triple extortion. Despite payment, there is no guarantee that stolen information has been destroyed, as seen in the University of Mississippi Medical Center attack, which disrupted operations at a healthcare system, including the only Level I trauma centre and Level IV neonatal intensive care unit in Mississippi.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at thearabianpost.com →

More in Tech

More from Wednesday 19 August →