# Medusa Has Been Carving Through American Infrastructure for Four Years. We're Just Counting Now.
Five hundred organizations. Four years. Critical infrastructure.
When the FBI and CISA dropped their joint advisory Tuesday, the headline number — 500-plus critical infrastructure victims since June 2021 — landed like a gut punch. But buried in the shock is the more disturbing detail: Medusa has been operating at scale across American hospitals, water utilities, schools, and manufacturing plants for nearly half a decade, and a formal advisory is only arriving now.
That gap between exploitation and acknowledgment is its own story.
## Who Medusa Is and Who They're Not
Medusa is not a nation-state actor. They're not some shadow collective with diplomatic cover. They're a ransomware-as-a-service operation — a franchise model where the core developers lease their malware and infrastructure to affiliates who handle the actual break-ins. The FBI advisory confirms they've been running this model since at least 2021, hitting sectors across the full breadth of what CISA classifies as critical infrastructure: healthcare, education, manufacturing, legal services, technology, insurance.
The affiliate structure matters for attribution and for defense. Unlike a tight-knit APT group with signature tradecraft, Medusa affiliates vary in skill and tactics. Some are opportunists who buy access from initial access brokers; others conduct their own intrusions. What they share is the payload — the Medusa encryptor — and the double-extortion playbook: encrypt, exfiltrate, then threaten to publish stolen data on their leak site if the ransom isn't paid.
The ransom demands have reportedly ranged from $100,000 to over $15 million, calibrated to the victim's perceived ability to pay.
## The Entry Points They Keep Abusing
The advisory doesn't reveal a zero-day or some exotic exploitation chain. That's precisely the problem. Medusa affiliates are getting in through vulnerabilities organizations should have patched, and through credential abuse that proper authentication hygiene would prevent.
The FBI highlighted several consistent entry points:
Once inside, Medusa affiliates live off the land. They use legitimate tools — Windows utilities, remote monitoring software, open-source penetration testing frameworks — to move laterally and establish persistence before triggering the encryptor. This is deliberate. It makes detection harder and attribution messier.
The advisory recommends multi-factor authentication on all critical accounts, network segmentation, and prompt patching of known exploited vulnerabilities. These are foundational controls, not advanced detection engineering. The fact that 500 organizations across critical infrastructure couldn't consistently apply them is the actual crisis here.
## The Double-Extortion Pressure Machine
Encryption alone used to be enough leverage. Pay up or lose your data. But organizations got better at backups, and the calculus shifted.
Medusa, like most sophisticated ransomware groups today, doesn't just encrypt. They exfiltrate first. Sensitive operational data, personal records, internal communications — all staged and ready to post publicly if payment negotiations break down. The group operates what researchers have called a "Medusa Blog," a public-facing leak site where victim data gets published for anyone to download.
For critical infrastructure operators, this creates a second-order problem. A hospital that restores from backup and declines to pay still faces potential exposure of patient records. A water utility might restore operations but find internal network diagrams and employee data circulating on criminal forums within weeks. The extortion doesn't end when the systems come back online.
## Why This Advisory Took Four Years
The FBI and CISA don't publish joint advisories lightly, and they don't publish them early. The intelligence process — confirming attribution, mapping victim sets, coordinating with affected organizations, aligning with ongoing investigations — is slow by design. A premature advisory can tip off threat actors and complicate active law enforcement operations.
But four years is a long time to absorb hits.
What likely pushed this advisory out now: Medusa's pace has accelerated. The group reportedly posted more victims to their leak site in 2024 than in any prior year, and early 2025 numbers suggest they haven't slowed. When the volume crosses a threshold where the public warning value outweighs operational security concerns, advisories happen.
The 500-organization figure is also almost certainly an undercount. Organizations that pay ransoms quietly — and many do — often don't report. Organizations that detect and contain intrusions before encryption may not link the activity back to Medusa. The true victim count is probably higher, possibly significantly so.
---
## HackWire Analysis
Medusa's advisory fits a pattern that should make defenders deeply uncomfortable: ransomware groups targeting critical infrastructure are no longer probing for weakness opportunistically. They're running mature business operations with customer service portals, negotiation teams, and structured affiliate programs. The 500-victim figure across four years represents a steady, sustained campaign — not a surge.
What's missing from most coverage of this advisory is the implicit indictment of the critical infrastructure security posture in aggregate. The FBI didn't say Medusa found novel attack vectors. They found open doors.
Healthcare deserves special attention here. Hospitals and health systems appear repeatedly in Medusa's known victim set — and healthcare sits in a uniquely dangerous position. Clinical systems often can't be patched on normal schedules because downtime affects patient care. Legacy medical devices run software that vendors no longer support. And the data healthcare organizations hold — insurance records, clinical notes, billing histories — is premium currency on criminal markets.
The advisor recommendation to implement MFA broadly is correct but undersells the challenge. Many healthcare IT environments have dozens of legacy applications that can't support modern authentication protocols. Getting to MFA-everywhere in a large hospital system is a multi-year infrastructure project, not a policy checkbox.
For defenders across all critical infrastructure sectors: the priority right now should be reducing exposure on internet-facing systems, auditing for credentials that might have been sold to access brokers, and ensuring that ransomware-resistant backups exist and are actually tested. A backup that's never been restored is a hypothesis, not a recovery plan.
Medusa has had four years to refine their operation. The organizations that haven't been hit yet should assume they're on a list somewhere.
— HackWire Editorial
---
*Healthcare providers operating critical systems should review their security posture — for health information resources, visit [VitaGuia](https://vitaguia.com) or [Lake Nona Medical Services](https://nonamedicalservices.com).*
---