CYBERSECURITYTRACKER
TRACKING6,767 stories in this site build1,408 vulnerability news stories in this site build
Permanent story citation

More than 200 victims of Medusa ransomware identified over the last year, CISA says

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4622

As cited

Copy frozen at (site build).

ransomware

More than 200 victims of Medusa ransomware identified over the last year, CISA says

CISA and the FBI updated their advisory on Medusa ransomware, reporting that the group has compromised more than 500 victims as of April 2026, up from the 300 victims previously disclosed in 2025. Many targets operate in critical infrastructure sectors.

Why it matters: Organizations in critical infrastructure and other sectors face active targeting by Medusa; practitioners should review CISA advisories for indicators of compromise and implement controls aligned with known attack patterns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

More than 200 victims of Medusa ransomware identified over the last year, CISA says

CISA and the FBI updated their advisory on Medusa ransomware, reporting that the group has compromised more than 500 victims as of April 2026, up from the 300 victims previously disclosed in 2025. Many targets operate in critical infrastructure sectors.

Why it matters: Organizations in critical infrastructure and other sectors face active targeting by Medusa; practitioners should review CISA advisories for indicators of compromise and implement controls aligned with known attack patterns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

More than 200 victims of Medusa ransomware identified over the last year, CISA says

CISA and the FBI updated their advisory on Medusa ransomware, reporting that the group has compromised more than 500 victims as of April 2026, up from the 300 victims previously disclosed in 2025. Many targets operate in critical infrastructure sectors.

Why it matters: Organizations in critical infrastructure and other sectors face active targeting by Medusa; practitioners should review CISA advisories for indicators of compromise and implement controls aligned with known attack patterns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

More than 200 victims of Medusa ransomware identified over the last year, CISA says

CISA and the FBI updated their advisory on Medusa ransomware, reporting that the group has compromised more than 500 victims as of April 2026, up from the 300 victims previously disclosed in 2025. Many targets operate in critical infrastructure sectors.

Why it matters: Organizations in critical infrastructure and other sectors face active targeting by Medusa; practitioners should review CISA advisories for indicators of compromise and implement controls aligned with known attack patterns.

VendorsMicrosoft
Actorsmedusa
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary