CISA Reports Medusa Ransomware Affects Over 500 Critical Infrastructure Organizations
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported that the Medusa ransomware operation has compromised more than 500 critical infrastructure organizations since 2021, marking a significant increase from over 300 reported last year. The threat group, which evolved into a ransomware-as-a-service model, targets sectors such as healthcare, government, defense, manufacturing, IT, and finance. Medusa recruits initial-access brokers (IABs) through cybercriminal forums to gain entry into victim networks, offering payments ranging from $100 USD to $1 million USD to these affiliates. CISA’s advisory emphasizes the need for network defenders to secure systems by patching vulnerabilities, segmenting networks to prevent lateral movement, and blocking access from untrusted sources to remote services. The report highlights the group’s use of stolen data to pressure victims into paying ransoms, underscoring the urgency for robust cybersecurity measures across critical infrastructure sectors. Security experts warn that Medusa’s expansion into a RaaS model poses a growing threat, requiring coordinated efforts to mitigate risks and protect national security interests.
