The U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued an urgent warning about the growing threat of Medusa ransomware. This ransomware-as-a-service (RaaS) operation has been actively targeting organizations worldwide since 2021 and has recently escalated its attacks across various industries.
Medusa Ransomware: A Growing Threat
According to the advisory released this week, Medusa actors primarily deploy phishing campaigns to steal victims’ credentials, gaining access to critical systems. The ransomware follows a double extortion model, encrypting data and threatening to leak stolen information unless a ransom is paid. Victims’ data is displayed on Medusa’s data-leak site, with countdown timers showing the remaining time before the information is released.
The advisory highlights that ransom demands are prominently posted, including direct links to cryptocurrency wallets associated with Medusa affiliates. Victims also have the option to delay data release by paying $10,000 in cryptocurrency per additional day.
Industries Under Attack
Since February 2025, Medusa ransomware has targeted over 300 victims across key sectors, including:
- Healthcare
- Education
- Legal Services
- Insurance
- Technology
- Manufacturing
Protecting Against Medusa Ransomware
Cybersecurity experts recommend the following measures to mitigate the risk of Medusa attacks:
- Regularly update and patch operating systems, software, and firmware.
- Implement multifactor authentication (MFA) for emails, VPNs, and other critical services.
- Use long, complex passwords instead of frequently changing weak passwords.
- Train employees to recognize and avoid phishing attempts.
Organizations are urged to strengthen their cybersecurity infrastructure and remain vigilant against phishing campaigns and unauthorized access attempts. The rise in Medusa ransomware incidents underscores the urgent need for proactive security measures to prevent costly breaches and data leaks.
For more updates on cybersecurity threats, stay tuned to our latest reports.