Bottom line: The FBI and CISA warn that the ransomware group Medusa has compromised more than 500 critical infrastructure organizations in the US since June 2021.
The FBI and CISA report that the ransomware group Medusa has compromised more than 500 critical infrastructure organizations in the US since June 2021. The advisory includes details on attack patterns and recommendations for defense.
According to the FBI, in an announcement published on Tuesday, the ransomware group Medusa has attacked more than 500 critical infrastructure organizations in the US since June 2021. The disclosure comes as part of a joint advisory from CISA, the FBI, and other agencies addressing the group’s tactics, techniques, and procedures (TTPs) as well as indicators of compromise.
For CISOs, the number of affected organizations points to the group’s reach and operational maturity. Medusa operates under a ransomware-as-a-service model, meaning the attack surface is not limited to a single actor but scales through affiliated groups. The sectors affected typically fall among those classified as critical, making the attacks particularly relevant from the perspective of national security agencies and potentially triggering regulatory reporting obligations as well as heightened scrutiny from supervisory authorities.
The CISA and FBI advisory contains concrete recommendations for hardening systems, including patch management for known exploited vulnerabilities, network segmentation, and multi-factor authentication for remote access. Security officers should incorporate the published indicators of compromise into existing detection systems and review internal ransomware incident playbooks in light of Medusa’s documented TTPs.
Source: www.bleepingcomputer.com · Published August 19, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.