11 views 10 secs 0 comments

#StopRansomware: Medusa Ransomware Update

In March 2025, CISA published an advisory on the Medusa ransomware gang. They have now updated it, noting:

 Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. As of April 2026, Medusa developers and affiliates—referred to as “Medusa actors” in this advisory—have impacted over 500 victims from a variety of critical infrastructure sectors. Affected industries include medical, education, legal, insurance, technology, and manufacturing. Per FBI, the Medusa ransomware variant is unrelated to the MedusaLocker variant and the Medusa mobile malware variant.

The authoring agencies encourage organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of Medusa ransomware incidents.

Download the .pdf version of the full report, or read it all online.

Previous coverage of Medusa attacks and analyses on The DataBreach Times can be found via the links here.