The Medusa ransomware-as-a-service (RaaS) gang and its affiliates attacked over 500 victim organizations between June 2021 and April 2025. According to a joint advisory from the US Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA), the group targeted the medical, education, legal, insurance, technology, and manufacturing sectors.

How Does Medusa Recruit Attackers?

The FBI reports that Medusa actors typically recruit what are known as "initial access brokers" (IABs) through cybercriminal forums to obtain entry into potential victim networks. This form of cybercrime has become big business: Medusa is known to offer payments of up to $1 million to IABs in exchange for access to a single organization.

How Does Medusa Gain Access to Victims?

Medusa actors rely on two primary techniques to compromise targets. First, phishing campaigns — carefully crafted emails sent to key staff members designed to steal credentials or install malware. Second, exploitation of unpatched software vulnerabilities. Medusa operates opportunistically, targeting organizations with known unaddressed flaws rather than focusing on any specific industry or sector.

Despite the historical taboo in cybercriminal circles against attacking hospitals, the healthcare and public health sector has become a frequent target of Medusa operations. That unwritten rule is now firmly in the past.

What Is Medusa's Double-Extortion Model?

Medusa RaaS uses a double-extortion strategy, meaning victims face two simultaneous threats: they must pay to decrypt their files and pay to prevent their stolen data from being publicly released. The ransom note demands victims make contact within 48 hours via either a Tor browser-based live chat or Tox, an end-to-end encrypted instant messaging platform. If a victim does not respond, Medusa actors escalate — contacting them directly by phone or email.

Medusa maintains an onion data leak site where it systematically publishes victims' sensitive information alongside countdown timers. The clock runs until the ransom is paid, piling psychological pressure on victims and their boards, legal teams, and insurers.

How Does Medusa Calculate Ransom Demands?

Medusa actors do their homework before setting a ransom figure. They research victims' financial details and base their demands on publicly available revenue data — ensuring demands are calibrated to what a target can plausibly pay. Actors offer a "lower rate" for quick payment, framing discounts as time-limited to accelerate victim decision-making.

After a ransom is paid, Medusa claims it will remove the victim's data from its leak site. However, the FBI warns that there is no way to verify this pledge — victims who pay have no guarantee their data will not be sold, leaked, or used again.

Key Takeaways for Organizations

The FBI and CISA urge organizations to prioritize timely software patching to eliminate the vulnerability entry points Medusa actively exploits. Additional recommended mitigations include multi-factor authentication, network segmentation, and staff training to identify phishing attempts. The advisory emphasizes that paying a ransom does not guarantee data recovery or deletion — and may mark the paying organization as a willing future target.