Summary
- A joint US government advisory says Medusa actors had affected more than 500 victims by April 2026 across critical infrastructure and other sectors.
- Microsoft tracks high-tempo Medusa activity in which exposed web-facing systems can be exploited and ransomware deployed within days or, in some cases, 24 hours.
- The campaign repeatedly uses vulnerable perimeter software, turning delayed patch deployment into an initial-access opportunity.
Medusa ransomware actors had affected more than 500 victims across critical infrastructure and other sectors by April 2026, according to an updated joint US government advisory, underlining the continued reach of an operation that has remained active despite repeated disruption efforts.
The Cybersecurity and Infrastructure Security Agency advisory, issued with the FBI and the Multi-State Information Sharing and Analysis Center, describes Medusa as a ransomware-as-a-service operation whose developers and affiliates have targeted organisations across multiple sectors.
The cumulative figure does not imply that all of the victims were hit recently. Reporting accompanying the latest update indicates that more than 200 victims were identified over the past year, while the government’s total count now exceeds 500 as of April.
Medusa attacks typically combine encryption with data theft and extortion. Victims can face demands for payment both to restore access and to prevent stolen information from being released publicly, increasing the operational and legal pressure generated by an intrusion.
Microsoft Threat Intelligence has separately linked a financially motivated actor it tracks as Storm-1175 to high-tempo Medusa operations. In research published in April, Microsoft said the actor repeatedly exploits vulnerable internet-facing systems, moving from initial access to data theft and ransomware deployment within a few days and, in some cases, within 24 hours.
Recent intrusions observed by Microsoft have affected healthcare, education, professional services, and financial organisations in the UK, Australia, and the United States. The actor has used both recently disclosed vulnerabilities and, in some cases, vulnerabilities before public disclosure.
Patch latency creates an operating window
The Medusa activity demonstrates how ransomware groups can turn ordinary vulnerability-management delays into an intrusion pipeline. Storm-1175 has exploited flaws in products including Microsoft Exchange, PaperCut, Ivanti Connect Secure, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, GoAnywhere MFT, SmarterMail, BeyondTrust, and SAP NetWeaver.
The common factor is not a single technology stack but exposure at the perimeter. Systems that are reachable from the internet and sit behind on patch deployment provide a route into environments where attackers can then establish persistence, steal credentials, disable or weaken security controls, move laterally, and prepare ransomware deployment.
Microsoft has observed Storm-1175 creating web shells or deploying remote-access payloads after exploitation, adding accounts for persistence, using remote-management software, stealing credentials, and changing Microsoft Defender Antivirus settings before the final ransomware stage. The actor has also used tools such as Rclone for exfiltration and PDQ Deploy for wider payload distribution.
The speed of that chain narrows the practical difference between vulnerability disclosure and incident response. Where an attacker can weaponise a newly disclosed issue in a day and reach ransomware deployment shortly afterwards, patching queues designed around slower monthly risk cycles can leave a meaningful exposure window.
Medusa’s cumulative victim count also shows why ransomware resilience cannot be assessed solely through the survival of individual criminal brands. Affiliates, developers, access brokers, and infrastructure can persist, move between operations, and reuse well-established techniques even as law enforcement and defenders disrupt parts of the ecosystem.
The advisory does not establish that every Medusa victim was compromised through the same actor or vulnerability, and ransomware-as-a-service operations can involve affiliates with different methods. The confirmed pattern is broader: exposed enterprise software continues to provide a repeatable route into organisations where ransomware operators can convert technical access into data loss and operational disruption.
With more than 500 known victims now associated with Medusa, the operation has moved well beyond an isolated ransomware family. Its scale, cross-sector reach, and exploitation tempo make it another example of how quickly known weaknesses in public-facing infrastructure can become business-continuity incidents.




