# Medusa Ransomware Targets Over 500 Critical Infrastructure Organizations

*Published August 21, 2026*
*Source: [https://www.infosecurity-magazine.com/news/critical-infrastructure-medusa/](https://www.infosecurity-magazine.com/news/critical-infrastructure-medusa/)*

## Executive Summary

The Medusa ransomware group has compromised over 500 critical infrastructure organizations, with a focus on healthcare, by exploiting unpatched vulnerabilities. This rapid exploitation, combined with enhanced techniques, poses significant challenges for security teams to mitigate threats effectively.

## Article

The Medusa ransomware group has affected more than 500 critical infrastructure organizations by April 2026, as reported in a recent advisory from the FBI. This advisory, which was released on August 18 in collaboration with the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services, highlights a troubling increase from a previous report in March 2025, which documented 300 affected organizations as of February 2025. Notably, the healthcare sector has been a frequent target of Medusa's attacks.

Since February 2025, Medusa has notably expanded its techniques and tools, enhancing its initial access and post-exploitation capabilities. Initially detected in June 2021, Medusa shifted from a closed operation to an affiliate model, broadening its reach. The group capitalizes on unpatched vulnerabilities, often exploiting them within 24 hours of disclosure, sometimes even before public announcements. Although Medusa does not develop its own zero-day vulnerabilities, its opportunistic nature allows it to target organizations with outdated software.

Recent developments include utilizing Interactsh dynamic URLs to identify compromised hosts and improve post-exploitation activities like network infiltration and lateral movement. Medusa actors employ advanced PowerShell techniques to conceal their activities and use tools like Nezha and GSocket for command and control operations. They also exploit legitimate remote monitoring and management software already present in victim environments.

The group employs tactics such as using Windows Task Manager Mimikatz for credential harvesting and integrating Bandizip and Rclone to facilitate data exfiltration. Medusa's encryptor, transferred via secure file transfer protocol, changes files to have a .medusa extension while terminating services and deleting shadow copies. The ransom note demands contact within 48 hours, with threats of data publication if demands are not met. Medusa's use of a double-extortion model compels victims to pay both for system restoration and to prevent data leaks.
