{
  "id": 2022983,
  "title": "Medusa ransomware breaches more than 500 organisations",
  "url": "https://urgent.news/2026/08/19/medusa-ransomware-breaches-more-than-500-organisations-2022983",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-19T21:16:46.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/medusa-ransomware-breaches-more-than-500-organisations/"
  },
  "original_language": "en",
  "account": "The Medusa ransomware group has targeted over 500 organizations across critical infrastructure sectors, according to a new joint cybersecurity advisory from the FBI, Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services. This represents a significant increase from the 300 victims identified in February 2025, reflecting the expansion of Medusa's ransomware-as-a-service operation since its emergence in June 2021. Affected sectors include healthcare, defense industrial base, critical manufacturing, government services and facilities, information technology, and financial services. Healthcare has become a particular target due to the potential impact on clinical services and the leverage stolen medical data provides for extortion. Medusa's attack methods have accelerated, with operators exploiting newly disclosed security flaws within 24 hours of their public disclosure, and vulnerabilities up to a week before anyone else is aware. The group's operations have evolved from a closed operation to an affiliate model where developers provide ransomware infrastructure to outside operators while retaining control over ransom negotiations. Initial access brokers play a crucial role, with Medusa offering payments ranging from $100 to $1 million for exclusive access to compromised organizations. Once inside a network, Medusa actors use credential-stealing tools, remote monitoring applications, and techniques leveraging existing software within the victim's environment, making malicious activity harder to distinguish from routine system management. Medusa's operation relies heavily on double extortion, stealing information before encrypting systems and threatening to publish or sell the data if payment is refused. The group's leak site displays victims with countdown timers, ransom demands, and cryptocurrency payment information. In some cases, victims who have already paid are contacted by other Medusa actors, increasing the risk of triple extortion. Ransom demands are sometimes tailored to a target's publicly available financial information, with faster payments attracting lower demands. Authorities warn that removing a victim from Medusa's leak site after payment does not guarantee that stolen information has been destroyed.",
  "summary": "Medusa ransomware operators have compromised more than 500 organisations across critical infrastructure sectors, prompting US cyber authorities to warn that the group is exploiting vulnerabilities faster and using increasingly aggressive methods to penetrate networks and extort victims. An updated joint cybersecurity advisory from the Federal Bureau of Investigation, Cybersecurity and…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Arabian Post",
        "title": "Medusa ransomware breaches more than 500 organisations",
        "url": "https://urgent.news/2026/08/19/medusa-ransomware-breaches-more-than-500-organisations",
        "published": "2026-08-19T21:16:46.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}