
Ransomware crews used to break in themselves. Medusa ransomware mostly buys its way in, and it now counts more than 500 critical infrastructure victims in the United States, up from roughly 300 a year ago. The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Health and Human Services (HHS) documented the shift in an updated joint advisory this week.
Medusa Ransomware Went From 300 Victims to Over 500 in a Year
In March 2023, Medusa posted a video of stolen files from the Minneapolis Public Schools district on its dark-web leak site, one of the attacks that pulled the gang out of obscurity. Medusa, a ransomware-as-a-service (RaaS) operation first identified in June 2021, has since become one of the most prolific extortion brands in cybercrime.
The advisory, first published in March 2025 and revised this month, now tallies victims across Healthcare and Public Health, the Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. More sit in the medical, education, legal, and insurance fields, the kind of operational disruption ransomware has caused elsewhere, including an attack that shut a hospital’s doors, elevators, and ventilation. Medusa is a crowded name in cybercrime, shared with an unrelated Android malware family and the separate MedusaLocker operation; this is neither.
Why Medusa Ransomware Buys Its Access Instead of Earning It
Medusa ransomware grew mostly by purchasing access. The advisory says its developers recruit initial access brokers (IABs), the criminal middlemen who sell ready-made footholds into corporate networks. Medusa offers these affiliates between $100 and $1 million to work exclusively for the group.
The 500-victim figure reads like a measure of Medusa’s reach. The operationally consequential read is different: the number measures the health of the access-broker market. When footholds are cheap and plentiful, a RaaS crew scales by buying them wholesale. The climb from about 300 victims in March 2025 to more than 500 by April 2026 tracks broker supply, not a leap in Medusa’s own tradecraft. The brokers get in the ordinary ways, through phishing and unpatched public-facing systems, the same edge-exploitation route that crews like Qilin have run against enterprise VPNs. If a broker can phish one of your help-desk staff or hit an unpatched gateway, that access is for sale, and Medusa is a buyer.
How to Close the Footholds Medusa Ransomware Pays For
The advisory’s mitigations line up with the broker supply chain: cut off the access before it is sold, then contain it if it lands.
Require phishing-resistant MFA on every remote-access path – Broker footholds usually start with a phished or reused credential, and the three agencies put phishing-resistant multifactor authentication (MFA) first for that reason.
Patch public-facing systems on the advisory’s schedule – Medusa’s brokers lean on unpatched operating systems, software, and firmware for initial access, so closing those exposures removes the inventory they resell.
Segment networks to break lateral movement – The FBI, CISA, and HHS pair segmentation with blocking untrusted access to internal remote services. That way a single bought foothold hits a dead end rather than spreading domain-wide.
The Minneapolis stolen-data video announced Medusa ransomware in 2023; the same leak site now lists more than 500 organizations, each one reached through a foothold that these mitigations would have priced out of the market.
Join our LinkedIn group Information Security Community!









