Skip to main content
LiMP VPN
All news

Medusa Ransomware: 500+ Critical Infrastructure Victims

Medusa Ransomware: 500+ Critical Infrastructure Victims

In short: The FBI and CISA updated their joint advisory AA25-071A: since 2021, the Medusa ransomware group has confirmed more than 500 critical infrastructure victims — hospitals, banks, defence contractors, and government agencies. The group runs double extortion: it steals medical records, financial data, and personal information before encrypting systems and demanding payment. The average ransom paid is $260,000; the largest documented case reached $15 million.

What is Medusa and why it is not just an American problem

Medusa is a ransomware group first observed in January 2021. Since 2023 it has operated as Ransomware-as-a-Service (RaaS): the encryptor authors lease it to affiliates who carry out attacks, splitting the ransom proceeds. On 8 September 2026, CISA, the FBI, and the U.S. Department of Health and Human Services published an updated advisory AA25-071A confirming more than 500 victims as of April 2026 — over 200 more than the February 2025 count.

This is only superficially an American problem. Hospitals, insurers, and banks store data for every person who has ever used their services, including customers from other countries. A breach of medical or financial records recognises no national borders. Stay up to date with the latest security incidents in the LiMP VPN news section.

Who was hit: 500+ victims across 7 sectors

According to the advisory, Medusa systematically targets organisations in seven critical infrastructure sectors:

  • Healthcare — the most targeted sector: hospitals, medical centres, laboratories, health insurers
  • Defence industrial base — U.S. Department of Defense contractors
  • Critical manufacturing — factories and industrial facilities
  • Government facilities — federal, state, and municipal agencies
  • Information technology
  • Financial services
  • Education, legal, and insurance organisations

Among the notable 2026 victims: the University of Mississippi Medical Center — the only children's hospital in the state, the only organ transplant centre, and the only Level I trauma centre. When ransomware encrypts the infrastructure of such a facility, the risk extends beyond personal data to patients in critical care.

Double extortion: data stolen before encryption

Classic ransomware encrypts files and demands a decryption key. Medusa uses a more dangerous two-stage model.

Stage 1 — data theft. Before deploying the encryptor, Medusa affiliates map the victim's network and exfiltrate valuable files using the Rclone and Bandizip utilities. The haul typically includes medical records, patient histories, employee and client personal data, financial documentation, and corporate secrets.

Stage 2 — encryption. Systems are locked by the gaze.exe encryptor (AES-256). The victim loses access to files and receives a ransom note with a 48-hour negotiation window via Tor chat or Tox messenger.

Extending the deadline costs $10,000 per day. If the organisation refuses to pay, all stolen data is published on the "Medusa Blog" — a dark-web leak portal where files are publicly downloadable. This is why backups do not fully solve the problem: data has already been exfiltrated and the publication threat remains regardless of whether encrypted systems are restored.

How attackers get in

The FBI and CISA identified several primary initial-access vectors:

  • Phishing emails — targeted attacks on employees of the victim organisation
  • Initial access brokers — purchasing existing access to previously compromised corporate networks
  • Unpatched vulnerabilities — Medusa weaponises public CVEs within 24 hours of disclosure, sometimes before a patch is available. Recent examples: CVE-2024-1709 (ScreenConnect authentication bypass), CVE-2023-48788 (Fortinet FortiClient EMS SQL injection), CVE-2026-1731 (BeyondTrust remote code execution)

Once inside, affiliates move laterally through the network using legitimate remote-management tools — RDP, AnyDesk, ConnectWise — mimicking normal IT activity to evade detection. Mimikatz is used for credential dumping. Encrypting your traffic with LiMP VPN reduces the risk of credential and session interception on public and shared Wi-Fi networks.

What it means for ordinary users

"Some hospital in the US got hacked — surely that has nothing to do with me?" Attacks on critical infrastructure affect everyone whose data is held there.

Medical data. Diagnoses, prescriptions, test results, and insurance records are held electronically by healthcare providers and insurers. Once published on a dark-web portal, they can be used for blackmail, insurance fraud, or employment discrimination.

Financial data. Attacks on banks and financial firms risk exposing transaction histories, account details, and loan information — all raw material for highly targeted phishing campaigns.

Government records. Breached municipal agencies expose addresses, tax records, and property registration data — often as valuable to criminals as banking credentials.

Protecting yourself from a breach of someone else's server is outside your control. But you can reduce the risk of your data being intercepted in transit: LiMP VPN encrypts your traffic and conceals from your ISP the fact that you are accessing financial and medical portals. See plans from $0.99/month.

How to protect yourself: FBI and CISA recommendations

  • Patch immediately — Medusa exploits public CVEs within 24 hours of disclosure. The faster you patch, the narrower the exposure window
  • Use phishing-resistant two-factor authentication — hardware security keys (FIDO2) or TOTP authenticator apps are more reliable than SMS codes
  • Keep offline, immutable backups — isolated encrypted backups cannot be locked by ransomware and enable recovery in a worst-case scenario
  • Use a VPN on public networks — credential and session interception on open Wi-Fi remains a key initial-access vector for Medusa affiliates

Sources

Medusa Ransomware: 500+ Critical Infrastructure Victims