More than 200 victims of Medusa ransomware identified over the last year, CISA says
ID: 9716aa4e-7fad-5f88-9e2c-6b0d26a3d322
STIX ID: report--9716aa4e-7fad-5f88-9e2c-6b0d26a3d322
Feed Name: The Record from Recorded Future News
CISA and the FBI updated an advisory reporting that the Medusa ransomware group has impacted over 500 victims as of April 2026, with a pronounced focus on healthcare and critical infrastructure; the advisory highlights Medusa’s rapid operationalization of newly announced (and sometimes pre-disclosure) exploits, affiliate model, extortion tactics (including ransom negotiation behaviors and leak site activity), use of credential-stealers and legitimate remote-access software to evade detection, and recruitment of initial access brokers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
