CISA and FBI Update Medusa Ransomware Advisory Identifying Over 500 Victims Across Critical Infrastructure
CISA, the FBI, and the Department of Health and Human Services updated the March 2025 #StopRansomware advisory on Medusa on Tuesday, reporting that the ransomware-as-a-service operation has hit more than 500 victims as of April, up from the 300 victims cited when the advisory first published
The update operationalizes new detection guidance rather than signaling a shift in threat trajectory: defenders across healthcare, manufacturing, and technology gain concrete hunting indicators, including Nezha backdoor signatures and Rclone staged in Defender exclusion folders, while newly added Fortra GoAnywhere and BeyondTrust exploitation shows affiliates continuing to outpace patch cycles. HHS joining as co-sealer formalizes healthcare targeting that was previously inferred rather than jointly attributed. Sourcing rests on the CISA advisory itself, with secondary outlets summarizing rather than independently corroborating, limiting sourcing depth despite high nominal convergence. The rise from over 300 to over 500 documented victims may reflect expanded FBI investigative reach and improved attribution rather than an actual acceleration in Medusa's attack tempo.
4 sources
- More than 200 victims of Medusa ransomware identified over the last year, CISA says -
The Record - #StopRansomware: Medusa Ransomware -
CISA - Medusa ransomware tallies hundreds of new victims, says updated advisory on group's tactics -
CyberScoop - Medusa ransomware slams critical infrastructure organizations -
Cybersecurity Dive