Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity News

Experts Weigh in on the Medusa Ransomware Gang

By Jordyn Alger, Managing Editor
Laptop half open
Daniel Korpai via Unsplash
August 24, 2026

The Medusa Ransomware gang has breached more than 500 organizations since June 2021, according to an advisory from the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS). 

Security Leaders Weigh In

Matthieu Chan Tsin, Senior Vice President, Resiliency Services at Cowbell:

The CISA advisory highlights a critical reality about Medusa’s evolution into a Ransomware-as-a-Service (RaaS) model: threat actors rarely break down the front door when they can buy key access from Initial Access Brokers (IABs) or exploit a third-party vendor. With Medusa’s campaigns targeting sector supply chains, attackers frequently leverage unpatched vulnerabilities in remote access protocols or compromise managed service providers to bypass primary defenses. To counter this, security teams must adopt continuous external attack surface monitoring. Prioritizing rigorous vulnerability management on remote-facing assets, enforcing robust Multi-Factor Authentication, and actively auditing third-party digital supply chains are essential steps to closing the entry points IABs exploit.

Medusa relies heavily on double-extortion tactics, so traditional offline backups are no longer a standalone safety net. Organizations must focus on strict network segmentation and implementing continuous credential monitoring to catch compromised logins before they are monetized on the dark web. Security leaders shouldn’t feel overwhelmed by these evolving RaaS models; by pairing automated threat detection with proactive hygiene, businesses can turn complex cyber threat intelligence into clear, manageable choices that neutralize intrusions long before they turn into operational downtime.

Matt Hartman, Chief Strategy Officer at Merlin Group:

Medusa’s growth from roughly 300 critical infrastructure victims to more than 500 underscores how compressed the ransomware attack cycle has become. Attackers are moving from vulnerability disclosure to exploitation much more rapidly, which means traditional patching timelines and reactive security models are increasingly inadequate. Security teams should treat advisories like this as actionable intelligence, not simply awareness. Immediately map CISA’s indicators, exploited vulnerabilities, and observed tactics against their own environments; prioritize remediation based on exposure and business impact; and actively hunt for evidence of compromise. The objective is to turn threat intelligence into defensive action before attackers can operationalize the same information.

John Gallagher, Vice President at Viakoo:

Two things are at play here; the time to exploitation continues to shrink, and there is more focus on ransomware-as-a-service aimed at OT and IoT systems.  We’ve seen a significant (>55%) rise in OT systems being held for ransom; it’s not about just stealing data, it’s holding critical systems for ransom. 

When the window from disclosure to exploitation collapses to a single day it shows we are well past patching on a monthly or quarterly basis.  Organizations must be prepared to deploy patches on an ongoing basis at scale.  

Ransomware operators increasingly treat internet-facing appliances, unmanaged devices, and edge infrastructure as their primary point of entry. Once initial access brokers get a foothold, they leverage native tools and remote access to move laterally. If your security posture stops at asset discovery and doesn’t automate the remediation with firmware updates, credential rotations, and certificate management you just cannot move fast enough to beat automated exploitation.

Organizations can improve their security posture in a few ways.  Medusa heavily leverages dual-use utilities (PowerShell, remote management tools) and stolen credentials rather than custom binaries. Enforce strict application control, disable unused remote access ports, and mandate zero-trust network segmentation between operational systems and general IT networks.  Likewise enforce routine, automated rotation of application, service-account, and device passwords alongside multi-factor authentication (MFA) across every external gateway.

KEYWORDS: Cybersecurity Infrastructure Security Agency ransomware threat intelligence

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

security

6 Crisis Response Best Practices (That Actually Hold Up When Things go Sideways)

Photograph of apartment complex patios

Enhancing Residential Building Security

Blurry photo of people moving through the mall

Violence Remains Top Concern for Retailers

5 Minutes with Johnson

Can Organizations Trust Their Own AI?

Patient in bed

When Cyberattacks Hit Medical Devices, Patients Pay the Price

Kaseware sponsored webinar

Events

August 25, 2026

Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

LIVE: August 25, 2026 at 2 PM EDT Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.

August 27, 2026

Leveraging AI & Mobility to Advance Your Security Domain

LIVE: August 27, 2026 at 2 PM EDT Explore how AI-driven cloud security solutions can elevate your security domain enhancing threat detection, streamlining operations, and delivering the resilience modern organizations demand.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Gloved hands typing on a lapop

    Experts weigh in on the MITRE nation-state cyberattack

    See More
  • Hotel resort

    Experts weigh in on Omni Hotel ransomware incident

    See More
  • Digital-Lock.jpg

    Experts weigh in on CIRCIA one year later

    See More

Related Products

See More Products
  • Physical Security and Safety: A Field Guide for the Practitioner

  • CASP.jpg.jpg

    CASP+ CompTIA Advanced Security Practitioner Certification All-In-One Exam Guide...

  • The Database Hacker's Handboo

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing