Federal cybersecurity agencies have identified over 200 new victims of the Medusa ransomware group in the past year, bringing the total confirmed victim count to more than 500 as of April 2026. This updated figure comes from an advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI, which was initially released in March 2025 and previously reported 300 victims by 2025. Many of the affected organizations operate within critical infrastructure sectors.
The Medusa group has shown a particular focus on the healthcare sector. A notable incident in April involved the shutdown of the University of Mississippi Medical Center, which serves as the state's only children's hospital, Level I trauma center, and Level IV neonatal intensive care unit, and houses its sole organ transplant program.
The advisory highlights Medusa's proficiency in exploiting newly announced vulnerabilities, often within 24 hours of public disclosure. In some observed instances, the group has leveraged exploits up to a week before a vulnerability is publicly revealed. However, there is no indication that Medusa actors develop their own zero-day or N-day vulnerabilities; instead, they appear to obtain advanced access to exploits from undisclosed sources or rapidly capitalize on newly announced exploits before potential victims can apply patches.
Medusa, which emerged in 2021, transitioned from a closed ransomware operation to an affiliate model in 2023. This model allows the group to sell its ransomware to other hackers, granting varying levels of access based on their experience and earnings. For less experienced affiliates, critical operations like ransom negotiation may be centrally managed by the developers.
The group typically researches companies before launching attacks, basing ransom demands on publicly available revenue figures. They often offer reduced ransoms for prompt payment. While Medusa claims to remove victim information from its leak site after a ransom is paid, CISA and the FBI note that there is no way to verify the true deletion of data. Victims are also frequently offered an option to extend the data release deadline by one day for a fee, often $10,000.
In one incident investigated by the FBI, a victim who had already paid a ransom was contacted by a separate Medusa actor. This second actor claimed the initial negotiator had stolen the payment and demanded a second payment, representing half of the original amount, to provide the "true decryptor." This could indicate a triple-extortion scheme or a lack of cohesion within the ransomware group's operations.
Medusa actively recruits members on cybercriminal forums and offers up to $1 million to initial access brokers who commit to working exclusively for the group. The CISA and FBI advisory provides technical guidance for organizations investigating Medusa attacks. The attackers are known to use various credential-stealing tools before deploying legitimate remote monitoring software to evade detection. Specific remote access software identified as used by Medusa actors includes AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop.
Since April, Medusa has not added any new victims to its leak site. This pause has led some experts to speculate that the high-profile attack on the University of Mississippi Medical Center may have attracted significant, unwanted law enforcement attention to the group. The group has consistently demonstrated a willingness to target healthcare facilities, as well as international and U.S. municipal governments.






