{
  "id": 2022980,
  "title": "Medusa ransomware breaches more than 500 organisations",
  "url": "https://urgent.news/2026/08/19/medusa-ransomware-breaches-more-than-500-organisations",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-19T21:16:46.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/medusa-ransomware-breaches-more-than-500-organisations-3/"
  },
  "original_language": "en",
  "account": "The Medusa ransomware group has compromised over 500 organizations across key infrastructure sectors, according to recent joint cybersecurity advisories from the FBI, Cybersecurity and Infrastructure Security Agency, and Department of Health and Human Services. This alarming figure represents a significant increase from 300 victims identified in February 2025, highlighting the rapid expansion of Medusa's ransomware-as-a-service operation since its emergence in June 2021. Critical sectors affected include healthcare and public health, defense industrial base, critical manufacturing, government services, IT, and financial services. Education, legal services, insurance, and technology have also been targeted.\n\nHealthcare has emerged as a primary focus for Medusa due to the immediate impact on clinical services and the substantial leverage gained through stolen medical information. The group's methods have accelerated, with operators exploiting newly discovered security flaws within 24 hours of public disclosure and vulnerabilities as much as a week before public knowledge, reducing the time available for defenders to patch systems. Despite not developing zero-day vulnerabilities themselves, Medusa is believed to acquire exploit information from various sources or rapidly exploit newly discovered weaknesses.\n\nInitially, Medusa functioned as a closed ransomware operation before transitioning to an affiliate model around 2023. Developers now provide ransomware infrastructure to outside operators while retaining control over aspects of the criminal enterprise, including ransom negotiations. Less experienced affiliates benefit from greater operational support from the core group, enabling Medusa to scale its operations without solely relying on a fixed team of attackers. Initial access brokers play a crucial role in this structure, with Medusa offering payments ranging from $100 to $1 million for access to compromised organizations, with higher rewards for brokers who work exclusively for the group.\n\nUpon infiltrating a network, Medusa actors employ credential-stealing tools, legitimate remote monitoring applications, and techniques leveraging software already present within the victim's environment. Remote-access products observed during attacks include AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop. The group's reliance on double extortion is evident, as it steals data prior to encryption and threatens to publish or sell the information if payment is not received. Medusa's leak site displays victims with countdown timers, ransom demands, and cryptocurrency payment information. Additional ransom demands, such as an extra day before publication for an additional $10,000, have also been observed. In some instances, victims have been contacted by different Medusa actors claiming the original negotiator has stolen the payment, raising concerns about triple extortion, though this may also be due to internal disputes or poor coordination within the ransomware network.\n\nRansom demands are sometimes tailored to a target's publicly available financial information, with faster payments attracting reduced demands. Authorities caution that removing a victim from Medusa's leak site after payment does not guarantee that stolen information has been destroyed. The consequences of Medusa's activities were starkly illustrated in an attack on the University of Mississippi Medical Center, which disrupted operations at a healthcare system that includes Mississippi's only children's hospital, Level I trauma center, and Level IV neonatal intensive care unit, forcing clinics to close temporarily and medical staff to rely on manual processes while systems were restored.",
  "summary": "Medusa ransomware operators have compromised more than 500 organisations across critical infrastructure sectors, prompting US cyber authorities to warn that the group is exploiting vulnerabilities faster and using increasingly aggressive methods to penetrate networks and extort victims. An updated joint cybersecurity advisory from the Federal Bureau of Investigation, Cybersecurity and…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Arabian Post",
        "title": "Medusa ransomware breaches more than 500 organisations",
        "url": "https://urgent.news/2026/08/19/medusa-ransomware-breaches-more-than-500-organisations-2022982",
        "published": "2026-08-19T21:16:46.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}