Experts Weigh in on the Medusa Ransomware Gang

The Medusa Ransomware gang has breached more than 500 organizations since June 2021, according to an advisory from the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS).
Security Leaders Weigh In
Matthieu Chan Tsin, Senior Vice President, Resiliency Services at Cowbell:
The CISA advisory highlights a critical reality about Medusa’s evolution into a Ransomware-as-a-Service (RaaS) model: threat actors rarely break down the front door when they can buy key access from Initial Access Brokers (IABs) or exploit a third-party vendor. With Medusa’s campaigns targeting sector supply chains, attackers frequently leverage unpatched vulnerabilities in remote access protocols or compromise managed service providers to bypass primary defenses. To counter this, security teams must adopt continuous external attack surface monitoring. Prioritizing rigorous vulnerability management on remote-facing assets, enforcing robust Multi-Factor Authentication, and actively auditing third-party digital supply chains are essential steps to closing the entry points IABs exploit.
Medusa relies heavily on double-extortion tactics, so traditional offline backups are no longer a standalone safety net. Organizations must focus on strict network segmentation and implementing continuous credential monitoring to catch compromised logins before they are monetized on the dark web. Security leaders shouldn’t feel overwhelmed by these evolving RaaS models; by pairing automated threat detection with proactive hygiene, businesses can turn complex cyber threat intelligence into clear, manageable choices that neutralize intrusions long before they turn into operational downtime.
Matt Hartman, Chief Strategy Officer at Merlin Group:
Medusa’s growth from roughly 300 critical infrastructure victims to more than 500 underscores how compressed the ransomware attack cycle has become. Attackers are moving from vulnerability disclosure to exploitation much more rapidly, which means traditional patching timelines and reactive security models are increasingly inadequate. Security teams should treat advisories like this as actionable intelligence, not simply awareness. Immediately map CISA’s indicators, exploited vulnerabilities, and observed tactics against their own environments; prioritize remediation based on exposure and business impact; and actively hunt for evidence of compromise. The objective is to turn threat intelligence into defensive action before attackers can operationalize the same information.
John Gallagher, Vice President at Viakoo:
Two things are at play here; the time to exploitation continues to shrink, and there is more focus on ransomware-as-a-service aimed at OT and IoT systems. We’ve seen a significant (>55%) rise in OT systems being held for ransom; it’s not about just stealing data, it’s holding critical systems for ransom.
When the window from disclosure to exploitation collapses to a single day it shows we are well past patching on a monthly or quarterly basis. Organizations must be prepared to deploy patches on an ongoing basis at scale.
Ransomware operators increasingly treat internet-facing appliances, unmanaged devices, and edge infrastructure as their primary point of entry. Once initial access brokers get a foothold, they leverage native tools and remote access to move laterally. If your security posture stops at asset discovery and doesn’t automate the remediation with firmware updates, credential rotations, and certificate management you just cannot move fast enough to beat automated exploitation.
Organizations can improve their security posture in a few ways. Medusa heavily leverages dual-use utilities (PowerShell, remote management tools) and stolen credentials rather than custom binaries. Enforce strict application control, disable unused remote access ports, and mandate zero-trust network segmentation between operational systems and general IT networks. Likewise enforce routine, automated rotation of application, service-account, and device passwords alongside multi-factor authentication (MFA) across every external gateway.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!







