Actor Profile

Medusa is a ransomware operation active since January 2021 that evolved from a closed ransomware variant into a Ransomware-as-a-Service (RaaS) model with an affiliate program. The gang recruits initial access brokers (IABs) through cybercriminal forums and marketplaces, offering payments between $100 and $1 million USD to affiliates, with opportunities for exclusive work arrangements. Medusa launched its leak site "Medusa Blog" in 2023 to pressure victims through data extortion tactics. The operation is distinct from MedusaLocker ransomware and other malware families sharing the Medusa name. The gang's primary motivation is financial gain through ransomware extortion targeting high-value critical infrastructure organizations.

TTPs (Tactics, Techniques, Procedures)

Medusa employs a RaaS affiliate model leveraging initial access brokers for victim compromise. The operation uses credential-based access as a primary initial access vector, followed by lateral movement across victim networks. The gang conducts data exfiltration prior to encryption to enable double extortion tactics, threatening to publish stolen data on their leak site if ransom demands are not met. Medusa affiliates exploit security vulnerabilities in operating systems, software, and firmware to gain and maintain access. The operation demonstrates capability for network reconnaissance and privilege escalation to impact multiple systems within targeted organizations. Key techniques align with credential abuse, exploitation of remote services, and data theft for extortion leverage.

Targets & Patterns

Medusa primarily targets critical infrastructure sectors in the United States, with over 500 organizations compromised since June 2021. Victim sectors include Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. Additional targets span medical, education, legal, insurance, technology, and manufacturing industries. The targeting pattern indicates a focus on high-value organizations with critical operational dependencies and likely willingness to pay ransoms to restore services. The breadth of sectors suggests opportunistic targeting based on access availability through IAB partnerships rather than sector-specific strategic objectives. Notable public victims include Minneapolis Public Schools (MPS) district in March 2023, demonstrating willingness to target educational institutions and leverage media attention for extortion pressure.

Historical Context

Medusa ransomware surfaced in January 2021 but remained relatively low-profile until 2023 when activity significantly increased following the launch of their leak site infrastructure. The operation transitioned from a closed ransomware variant to a full RaaS model during this period. CISA, FBI, and HHS issued a joint advisory in March 2025 reporting over 300 victims, which was updated in August 2026 to reflect over 500 victims as of April 2026, indicating sustained and escalating operational tempo. The March 2023 Minneapolis Public Schools attack marked a turning point in the gang's public profile, with the threat actors sharing video evidence of stolen data to demonstrate their capabilities and pressure victims. The operation's growth trajectory shows consistent expansion of affiliate recruitment and victim targeting over a five-year period.

Defensive Recommendations

  • Implement rigorous patch management to mitigate security vulnerabilities in operating systems, software, and firmware that Medusa affiliates exploit for initial access and privilege escalation
  • Deploy network segmentation to restrict lateral movement and contain ransomware propagation after initial compromise, limiting impact to critical infrastructure systems
  • Enforce multi-factor authentication (MFA) and monitor for credential abuse, as Medusa operations rely heavily on valid credentials to evade detection once initial access is achieved
  • Block remote service access from untrusted origins and implement zero-trust network access controls to prevent initial access broker exploitation of exposed services
  • Establish robust data loss prevention (DLP) and network monitoring to detect exfiltration attempts before encryption, as Medusa employs double extortion tactics requiring data theft
  • Maintain offline, encrypted backups with regular testing to enable recovery without ransom payment, reducing leverage of encryption-based extortion

---

# Geopolitical Context

Geopolitical Context

The sustained campaign by the Medusa ransomware-as-a-service operation against US critical infrastructure represents a persistent criminal threat to national security and economic stability. Since June 2021, the group has systematically targeted sectors essential to US national resilience—including healthcare, defense industrial base, critical manufacturing, government services, IT, and financial services. The evolution from a closed ransomware variant to a RaaS model with affiliate recruitment demonstrates the professionalization and scalability of cybercriminal ecosystems. The group's use of initial access brokers and payment structures ranging from $100 to $1 million USD reflects a mature criminal enterprise capable of sustained operations against hardened targets. The joint advisory from CISA, FBI, and HHS underscores the cross-sectoral nature of the threat and the US government's prioritization of critical infrastructure defense as a national security imperative.

State Actor Alignment

No state actor attribution is provided in the reporting. Medusa operates as a financially motivated cybercriminal ransomware-as-a-service operation recruiting affiliates through underground forums and marketplaces. While ransomware groups occasionally exhibit geographic patterns or tacit state tolerance, no evidence links Medusa to state sponsorship or strategic objectives beyond financial gain. The operation's targeting of US critical infrastructure may attract law enforcement and intelligence scrutiny, particularly given potential overlaps with sectors subject to sanctions enforcement and national security regulations. US authorities have historically pursued disruption operations, sanctions designations, and indictments against ransomware operators and their infrastructure, though no such actions against Medusa are reported at this time.

Business Impacty pro region

The impact is concentrated within the United States, affecting critical infrastructure sectors that underpin economic activity, public safety, and national defense. The breach of over 500 organizations—nearly doubling from 300 in March 2025—signals an acceleration in tempo and reach. Healthcare sector targeting raises public health continuity concerns, while defense industrial base compromises may threaten supply chain integrity and classified or controlled unclassified information. The advisory's emphasis on network segmentation and vulnerability mitigation reflects lessons learned from previous ransomware incidents that cascaded across interconnected systems. For US allies and partners, particularly in Europe and the Indo-Pacific, the Medusa campaign illustrates the transnational nature of ransomware threats and the importance of coordinated defensive measures, information sharing, and collective resilience frameworks. The RaaS model's reliance on initial access brokers suggests a global supply chain of compromised credentials and vulnerabilities that transcends national borders.

Forecast

If Medusa continues to operate without significant law enforcement disruption, the group is likely to expand its victim base and refine its affiliate recruitment and operational security practices. The RaaS model's scalability suggests that additional critical infrastructure sectors may be targeted, particularly those with lower cybersecurity maturity or legacy system vulnerabilities. Should US or international authorities pursue takedown operations, indictments, or sanctions—as has occurred with other major ransomware groups—Medusa may rebrand, fragment, or shift infrastructure to evade attribution and enforcement. If the group's leak site and data extortion tactics continue to generate revenue, copycat operations may adopt similar models, further saturating the ransomware threat landscape. Enhanced defensive measures, including the mitigation strategies outlined by CISA, FBI, and HHS, may reduce the attack surface, though the persistent availability of initial access brokers and exploitable vulnerabilities will likely sustain some level of intrusion activity in the near to medium term.