CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5825

As cited

Copy frozen at (site build).

ransomware

Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs

Cybersecurity agencies have issued an updated advisory on Medusa, a ransomware-as-a-service (RaaS) group that has now claimed over 500 critical infrastructure victims, up from 300 in March 2025. Since transitioning to the RaaS model in early 2023, the group has dramatically accelerated attacks by recruiting affiliates and initial access brokers, rapidly incorporating exploits for newly disclosed vulnerabilities including CVE-2026-1731 and CVE-2025-10035 within days of announcement. Medusa uses phishing, living-off-the-land tools, and legitimate remote access software to establish persistence, exfiltrate data, and deploy encryption, with particular prevalence in healthcare and public health organizations.

Why it matters: Healthcare, critical infrastructure, and education organizations face imminent risk from a highly active, well-resourced RaaS group that exploits unpatched vulnerabilities faster than most organizations can patch; immediate vulnerability remediation, network segmentation, and multifactor authentication are essential to reduce exposure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs

Cybersecurity agencies have issued an updated advisory on Medusa, a ransomware-as-a-service (RaaS) group that has now claimed over 500 critical infrastructure victims, up from 300 in March 2025. Since transitioning to the RaaS model in early 2023, the group has dramatically accelerated attacks by recruiting affiliates and initial access brokers, rapidly incorporating exploits for newly disclosed vulnerabilities including CVE-2026-1731 and CVE-2025-10035 within days of announcement. Medusa uses phishing, living-off-the-land tools, and legitimate remote access software to establish persistence, exfiltrate data, and deploy encryption, with particular prevalence in healthcare and public health organizations.

Why it matters: Healthcare, critical infrastructure, and education organizations face imminent risk from a highly active, well-resourced RaaS group that exploits unpatched vulnerabilities faster than most organizations can patch; immediate vulnerability remediation, network segmentation, and multifactor authentication are essential to reduce exposure.

VendorsConnectWiseFortinetMicrosoft
Actorsmedusa
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary