Medusa ransomware has breached more than 500 critical infrastructure organizations in the United States since June 2021, according to a joint advisory from the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, and the Department of Health and Human Services reported by BleepingComputer. The agencies said that, as of April 2026, Medusa actors had impacted more than 500 victims across multiple critical infrastructure sectors. BleepingComputer reports that the impacted sectors include Healthcare and Public Health, the Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. The advisory also lists other affected organizations in medical, education, legal, insurance, technology, and manufacturing industries. The figure marks an increase from the agencies’ March 2025 joint report, which estimated that Medusa had impacted more than 300 critical infrastructure organizations. The updated advisory raises the federal tally from more than 300 to more than 500. The agencies’ defensive guidance is direct: mitigate security vulnerabilities in operating systems, software, and firmware; segment networks to limit lateral movement after a compromise; and block access from untrusted origins to remote services on internal systems. The recommendations address exploitation attempts and lateral movement after compromise, according to the advisory language cited by BleepingComputer. BleepingComputer reports that Medusa first surfaced in January 2021, but its activity picked up in 2023 after it launched the Medusa Blog leak site. The group then used stolen data as leverage to pressure victims into paying ransoms, according to the report. The operation also changed form. BleepingComputer says Medusa began as a closed ransomware variant, then evolved into a ransomware-as-a-service operation with an affiliate model. The advisory says Medusa developers recruit initial access brokers in cybercriminal forums and marketplaces to obtain access to potential victims, with potential affiliate payments ranging from $100 to $1 million. The naming matters for defenders and incident responders. BleepingComputer notes that “Medusa” has been used by multiple malware families and cybercrime operations, including an Android malware-as-a-service operation also known as TangleBot and a Mirai-based botnet with ransomware capabilities. The Medusa ransomware operation covered by the advisory is also separate from MedusaLocker, despite frequent confusion between the names. The report adds that Medusa drew broader media attention in March 2023 after claiming an attack on Minneapolis Public Schools and sharing a video of stolen data. The latest advisory puts that activity into a larger federal tally: more than 500 victims across multiple critical infrastructure sectors. Who benefits: Security teams that can quickly map the advisory’s recommendations to existing controls have the clearest near-term advantage. Who's exposed: The advisory names multiple critical infrastructure sectors and also lists victims in medical, education, legal, insurance, technology, and manufacturing industries. Its recommended mitigations focus on vulnerabilities, network segmentation, and remote-service access from untrusted origins.