500 Critical Infrastructure Organizations, 13 Months, One Ransomware Group
CISA, the FBI, and the Department of Health and Human Services published a joint advisory this week confirming that Medusa ransomware has breached more than 500 U.S. critical infrastructure organizations since June 2021.
As of April 2026, that count had grown from an estimated 300+ organizations reported in March 2025.
67% growth. 13 months.
The sectors hit
Healthcare and Public Health. Defense Industrial Base. Critical Manufacturing. Government Services and Facilities. Information Technology. Financial Services.
Not opportunistic targeting — deliberate sector selection. Healthcare for ransom pressure (patient care disruption forces payment). Defense Industrial Base for intellectual property (weapons systems, classified programs, supply chain access). Critical Manufacturing for operational leverage (production lines, quality control, safety systems). Government for citizen data. Financial Services for transaction records. IT for supply chain multiplication (one managed service provider breach affects hundreds of downstream customers).
How they're getting in
Since February 2025, Medusa expanded techniques and tooling to enhance initial access and post-exploitation. CISA observed the group incorporating new exploits within 24 hours of vulnerability announcement.
In some cases, they're exploiting vulnerabilities a week before public disclosure.
Pre-announcement exploitation means Medusa operators have access to vulnerability information before the rest of the world gets the CVE number — researcher connections, dark web intelligence, or independent discovery. 24-hour post-announcement adoption means they're monitoring disclosure feeds and weaponizing faster than most organizations can determine whether they're affected, let alone patch.
What happens inside
Medusa operates as ransomware-as-a-service. Operators provide the ransomware, infrastructure, negotiation, and leak site. Affiliates handle initial access and deployment.
Double-extortion: encrypt the systems and exfiltrate the data. Victims face operational downtime plus the threat of a public data leak, regulatory notification requirements, and reputation damage. Medusa runs a dedicated leak site. If the ransom goes unpaid, victim data gets published.
The group targets backups — deletes Volume Shadow Copies, disables backup software, encrypts backup repositories. If you can't restore, you're left with two choices: pay or lose the data.
Lateral movement from initial foothold to domain controllers, file servers, databases, and backup systems. Comprehensive compromise before the encryption triggers. By the time the ransom note appears, they've been inside for days or weeks.
Credential theft: Active Directory dumps, LSASS memory, SAM hashes. Persistent access. Re-entry after remediation.
The healthcare impact
In healthcare, Medusa attacks mean EHR downtime, appointment cancellations, procedure delays, patient diversions to other hospitals, and reversion to manual paper records. Medications get prescribed by hand. Lab results get faxed. Imaging studies sit on film nobody can read anymore because the radiologists trained on PACS.
People delay care. Elective surgeries get canceled. Cancer treatments get postponed. Cardiac catheterizations wait. Hospital patient volume drops significantly in the first week after a ransomware attack, with recovery taking weeks.
And the data: patient names, dates of birth, Social Security numbers, addresses, diagnoses, medications, lab results, treatment histories, insurance information, payment records. HIPAA breach notification gets triggered. Covered entities must notify affected patients within 60 days, notify HHS Office for Civil Rights if the breach affects 500 or more people, and notify media if 500 or more people in a state are affected.
The Defense Industrial Base angle
Defense contractors hold engineering designs, manufacturing processes, classified research, and contract details. A breach doesn't just cost the company — it exposes programs that other countries would pay for.
Ransomware operators encrypt and demand payment. Nation-state actors buy the exfiltrated data on the side. Espionage layered on top of extortion.
The IT sector multiplier
When Medusa hits a managed service provider, the blast radius extends to every customer that MSP supports. One breach, hundreds of downstream victims. Software vendors get compromised, and every user of that software inherits the risk. Cloud providers get hit, and multi-tenant isolation becomes the only thing standing between one customer's breach and everyone else's data.
Supply chain attacks used to be the theoretical risk nobody prioritized. Medusa is making them routine.
The federal response
If Medusa exploits appear on CISA's Known Exploited Vulnerabilities catalog, federal agencies face mandatory patch deadlines. HIPAA requires healthcare entities to notify patients, HHS OCR, and media within 60 days of a breach. The FBI tracks Medusa operators and affiliates. International cooperation. Sanctions. Indictments. Seizures.
Arrests, though, remain rare — especially when the operators are Russia-based and operating in jurisdictions that don't extradite.
The question nobody's answering
500+ organizations. 67% growth in 13 months. Exploits weaponized within 24 hours of disclosure, sometimes before.
At what point does "improve your patch management" stop being useful advice and start being a way to avoid saying the system is designed wrong?
The infrastructure wasn't built for adversaries who move this fast. The procurement cycles, the compliance frameworks, the change-management processes, the testing requirements — all of it assumes you have time.
Medusa is proving you don't.
Source: CISA, FBI, HHS Joint Cybersecurity Advisory AA25-071A (updated August 2026; as of April 2026, 500+ critical infrastructure organizations breached by Medusa ransomware since June 2021, up from 300+ reported in March 2025). Medusa affiliates observed incorporating new exploits within 24 hours of CVE announcement; in some cases, exploiting vulnerabilities week prior to public disclosure.