Medusa is a ransomware-as-a-service operation active since June 2021 that has hit more than 300 organisations by the US government’s count and 161 by ours, where every incident is confirmed against a public source. It gets in through phishing and unpatched edge software, steals data before encrypting, and gives victims 48 hours to talk, at $10,000 a day to buy more time. Healthcare, education and government make up 57% of its confirmed victims, and 62% are in the United States.
This profile combines the joint CISA, FBI and MS-ISAC advisory on the group with the Ransomnews confirmed-attacks dataset, which records only incidents a victim, regulator or credible outlet has put on the record. The two numbers differ because they measure different things: the government counts claimed victims, we count confirmed ones. Both are worth having.
Who is behind Medusa ransomware?
Medusa started as a closed operation in 2021 and later opened up to affiliates while keeping the money in the developers’ hands. According to the joint advisory published on 12 March 2025, the developers recruit initial access brokers on criminal forums and pay them between $100 and $1 million for a way in, but “important operations such as ransom negotiation are still centrally controlled by the developers.” That hybrid structure matters for defenders: the person who broke into your network and the person you end up talking to are usually not the same people.
The name causes confusion, so a note on what Medusa is not. It is not MedusaLocker, a separate ransomware family that has been around since 2019, and it is not the Medusa Android banking trojan. The advisory makes the same distinction. When a breach notice or a leak-site post says Medusa in 2026, it almost always means this group, whose leak site the industry sometimes calls Medusa Blog.
How many victims has Medusa claimed?
Over 300 as of February 2025, according to CISA, spread across critical infrastructure sectors including medical, education, legal, insurance, technology and manufacturing. The Record put the pace at more than 200 victims in the twelve months before the advisory. Those are claims counted from the group’s own leak site, and leak-site claims include exaggerations, re-listings and victims who never confirm anything.
Our dataset holds 161 confirmed Medusa incidents between January 2023 and March 2026. The year-by-year shape is the useful part: 44 confirmed incidents in 2023, 72 in 2024, 37 in 2025 and 8 so far in 2026. Recent months always fill in as disclosures arrive, so the 2025 and 2026 figures will rise, but the peak in 2024 is real. That was the year the group’s largest known breaches landed, and it is also the year the affiliate model appears to have scaled.
| Sector | Confirmed incidents | Share |
|---|---|---|
| Healthcare | 38 | 24% |
| Education | 28 | 17% |
| Government | 26 | 16% |
| Financial services | 12 | 7% |
| Technology | 10 | 6% |
| Manufacturing | 9 | 6% |
| All other sectors | 38 | 24% |
Geographically the group is an American problem first. 100 of the 161 confirmed incidents, 62%, are in the United States, followed by Australia with 10, the United Kingdom with 7, and France and Canada with 4 each. Thirty countries appear in total. Part of that US share is disclosure law rather than targeting: American breach-notification rules push incidents onto the public record that would stay private elsewhere.
What are Medusa’s biggest known attacks?
Measured by records exposed, the largest confirmed Medusa incidents are all healthcare. Summit Pathology in Colorado disclosed 1.81 million people affected after an April 2024 attack. SimonMed Imaging in Arizona, hit in January 2025, reported 1.28 million. Insightin Health in Maryland reported 1.14 million after a September 2025 incident. Across the 68 confirmed Medusa incidents that disclosed a figure at all, 6.09 million records were exposed, and the true number is higher, because 93 incidents never published one.
Outside the US, the intermunicipal waste company Limburg.net in Belgium refused to pay after a November 2023 attack that exposed 292,734 records, one of 23 confirmed Medusa victims on record as refusing. Not one of the 161 is on the public record as having paid. That does not mean nobody paid; 138 incidents give no indication either way, and most victims never say. It does mean that in every case where a Medusa victim’s decision became public, the decision was no. Our payment-rate analysis explains why that pattern holds across groups.
How does Medusa get into a network?
Two ways, both ordinary. The advisory names phishing as the primary route for stealing credentials, and exploitation of unpatched software as the second, citing CVE-2024-1709, the ConnectWise ScreenConnect authentication bypass, and CVE-2023-48788, a SQL injection flaw in Fortinet’s EMS. Neither is exotic. Both had patches available before Medusa affiliates used them, which is the pattern across the whole initial-access market: brokers sell what the slowest patchers leave open.
// Free tool
How does your own site score?
Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.
No signup. Nothing installed. We only request what your site already serves publicly.
Once inside, the affiliates work almost entirely with legitimate tools. The advisory lists AnyDesk, Atera, ConnectWise, eHorus, N-able, PDQ Deploy, SimpleHelp and Splashtop for remote access, plain RDP, PowerShell and cmd.exe for execution, certutil for file movement, Advanced IP Scanner and SoftPerfect Network Scanner for discovery, Ligolo and Cloudflared for tunnelling, and Mimikatz for credentials. To blind defenders they bring their own vulnerable signed drivers to kill endpoint detection, a technique the industry shortens to BYOVD. The attack is a chain of administration software used by someone who is not your administrator, which is why “block malware” is the wrong mental model and “notice a new remote-access tool” is the right one.
How does a Medusa ransom demand work?
Medusa is a double-extortion operation: data is stolen first, then systems are encrypted, and the ransom buys both a decryptor and a promise not to publish. The ransom note demands contact within 48 hours through a Tor-based live chat or Tox, and if the victim does not respond, the group has been known to reach out directly by phone or email. The leak site then runs a countdown. Victims can pay $10,000 in cryptocurrency to add a day to the timer, a mechanism that turns the deadline itself into a revenue line.
The advisory also records the incident that earned Medusa a reputation for triple extortion. After one victim paid, a second Medusa actor made contact, claimed the negotiator had stolen the payment, and asked for half the amount again. Whether that was an internal fraud or a deliberate second bite, it is the clearest illustration on the record of why paying does not close a case. Our guide to negotiation tactics treats every group as capable of the same move, and our explainer on whether paying is even legal covers the sanctions risk before you get that far.
How do you defend against Medusa?
The mitigations follow directly from the tradecraft, and CISA’s top five are the ones that would have stopped most of the 161 confirmed incidents. Patch operating systems, software and firmware, with internet-facing remote-management and VPN products first, because those are the two named CVEs. Require multifactor authentication on every service, including VPN and webmail, because phishing for credentials is the primary route. Segment the network so a single foothold cannot reach backups and hypervisors, since the affiliates go for virtualisation hosts deliberately. Keep multiple offline copies of critical data. And disable command-line and scripting for users who do not need it, which cuts off the living-off-the-land toolkit.
One addition from the data. Healthcare, education and government account for 92 of the confirmed Medusa victims, and those are the sectors with the most third-party remote-access software installed and the least ability to take it offline. An inventory of every remote-management agent on the estate, with an alert on any new one, catches Medusa’s post-access phase in the window before encryption. It is unglamorous and it works.
Frequently asked questions
What is Medusa ransomware?
Medusa is a ransomware-as-a-service operation first identified in June 2021 that steals data, encrypts networks and threatens to publish what it took. It recruits affiliates for initial access but keeps ransom negotiation under the developers’ control. It is unrelated to MedusaLocker and to the Medusa Android malware.
How many victims has Medusa ransomware had?
More than 300 as of February 2025 according to CISA and the FBI, counting claims on the group’s leak site. Ransomnews has confirmed 161 Medusa incidents against public sources between January 2023 and March 2026, with 72 of them in 2024, the group’s peak year.
Who does Medusa ransomware target?
Healthcare, education and government bodies make up 57% of confirmed Medusa victims, and 62% of all confirmed victims are in the United States. The group also has confirmed victims in Australia, the United Kingdom, France, Canada and 25 other countries.
How does Medusa ransomware gain access?
Mainly through phishing for credentials and through unpatched internet-facing software. The joint advisory names CVE-2024-1709 in ConnectWise ScreenConnect and CVE-2023-48788 in Fortinet EMS as exploited vulnerabilities.
Does Medusa ransomware steal data?
Yes. Medusa runs double extortion, exfiltrating data before encryption and publishing it on a leak site if the ransom is not paid. Victims get 48 hours to make contact and can pay $10,000 per day to extend the countdown.
Is Medusa the same as MedusaLocker?
No. MedusaLocker is a separate ransomware family dating from 2019. The US government advisory on Medusa states explicitly that the two are distinct, as is the Medusa mobile banking malware.
What should organisations do to protect against Medusa?
Patch internet-facing remote-management and VPN software promptly, enforce multifactor authentication everywhere, segment networks so backups and hypervisors are isolated, keep offline backups, restrict scripting for ordinary users, and alert on any new remote-access tool appearing on the estate.
Sources and further reading
- CISA, FBI and MS-ISAC, #StopRansomware: Medusa Ransomware, advisory AA25-071A, 12 March 2025
- The Record: more than 200 victims of Medusa ransomware identified over the last year, CISA says
- BankInfoSecurity: Medusa ransomware hack of pathology lab affects 1.8 million
- Medusa on Ransomtracker, the live leak-site feed for the group
- The new mid-tier RaaS contenders: Qilin, Medusa, Embargo
- Why hospital ransomware attacks keep getting worse
- The Ransomnews threat-group catalogue
The Ransomnews Monthly
One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.
Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.
