LIVE · cybersecurity feed
Live wire
ransomwarecritical

More than 200 victims of Medusa ransomware identified over the last year, CISA says

The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.

zeroday.news ·

Federal cybersecurity agencies have identified over 200 new victims of the Medusa ransomware group in the past year, bringing the total confirmed victim count to more than 500 as of April 2026. This updated figure comes from an advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI, which was initially released in March 2025 and previously reported 300 victims by 2025. Many of the affected organizations operate within critical infrastructure sectors.

The Medusa group has shown a particular focus on the healthcare sector. A notable incident in April involved the shutdown of the University of Mississippi Medical Center, which serves as the state's only children's hospital, Level I trauma center, and Level IV neonatal intensive care unit, and houses its sole organ transplant program.

The advisory highlights Medusa's proficiency in exploiting newly announced vulnerabilities, often within 24 hours of public disclosure. In some observed instances, the group has leveraged exploits up to a week before a vulnerability is publicly revealed. However, there is no indication that Medusa actors develop their own zero-day or N-day vulnerabilities; instead, they appear to obtain advanced access to exploits from undisclosed sources or rapidly capitalize on newly announced exploits before potential victims can apply patches.

Medusa, which emerged in 2021, transitioned from a closed ransomware operation to an affiliate model in 2023. This model allows the group to sell its ransomware to other hackers, granting varying levels of access based on their experience and earnings. For less experienced affiliates, critical operations like ransom negotiation may be centrally managed by the developers.

The group typically researches companies before launching attacks, basing ransom demands on publicly available revenue figures. They often offer reduced ransoms for prompt payment. While Medusa claims to remove victim information from its leak site after a ransom is paid, CISA and the FBI note that there is no way to verify the true deletion of data. Victims are also frequently offered an option to extend the data release deadline by one day for a fee, often $10,000.

In one incident investigated by the FBI, a victim who had already paid a ransom was contacted by a separate Medusa actor. This second actor claimed the initial negotiator had stolen the payment and demanded a second payment, representing half of the original amount, to provide the "true decryptor." This could indicate a triple-extortion scheme or a lack of cohesion within the ransomware group's operations.

Medusa actively recruits members on cybercriminal forums and offers up to $1 million to initial access brokers who commit to working exclusively for the group. The CISA and FBI advisory provides technical guidance for organizations investigating Medusa attacks. The attackers are known to use various credential-stealing tools before deploying legitimate remote monitoring software to evade detection. Specific remote access software identified as used by Medusa actors includes AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop.

Since April, Medusa has not added any new victims to its leak site. This pause has led some experts to speculate that the high-profile attack on the University of Mississippi Medical Center may have attracted significant, unwanted law enforcement attention to the group. The group has consistently demonstrated a willingness to target healthcare facilities, as well as international and U.S. municipal governments.

ransomwarepatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Clop created custom web shell for Windchill data theft attacks

A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]

ransomware

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics

The updated warning from the FBI, CISA and HHS draws on a year’s worth of investigations to detail how the group gains initial access and what it does afterward. The post Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics appeared first on CyberScoop.

aicritical

OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue

The ChatGPT maker says its upcoming Astra model may have reached “critical” cyber capabilities, prompting it to halt a significant number of training runs while it tightens internal safeguards.

CVE-2026-68820high

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing [

ai

Project noRecognition: Teaching AI to Fool Surveillance Cameras

Researchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use. The Kansas City-based cybersecurity researcher Bill Swearingen spent the past year doing something that sounds almost too simple to work: printing patterns, watching cameras fail to detect them, and repeating. TechCrunch reports that after roughly […

security

University of Texas forced to take systems offline in San Antonio after cyberattack

The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response.