More than 200 victims of Medusa ransomware identified over the last year, CISA says
CISA updates its Medusa ransomware advisory: over 500 victims since early 2025, heavily targeting critical infrastructure — a trajectory European essential-service operators cannot ignore.
Summary written by editorial AI · Source link below
The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.
Editorial Analysis
Medusa's accelerating victim count across critical infrastructure sectors directly parallels NIS2-regulated industries in Europe, making proactive hardening urgent.
Test your ransomware IR playbook against a Medusa-style scenario and validate that offline backup restoration meets your RTO targets.
Medusa ransomware has compromised over 500 organisations in critical sectors — board-level assurance of ransomware resilience is overdue.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at The Record in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d