Ledger Nano X - The secure hardware wallet

500 Organizations Breached as Medusa Ransomware Spreads Through Critical U.S. Infrastructure

A ransomware group is expanding its attacks on U.S. critical infrastructure after hitting more than 500 organizations.

Federal agencies say the ransomware-as-a-service variant has now affected sectors including healthcare, defense, manufacturing, government services, information technology and financial services, says CISA.

The update to advisory AA25-071A marks an increase from the more than 300 victims noted in the March of 2025 version.

Medusa actors use a double-extortion approach that encrypts systems and threatens to release stolen data unless a ransom is paid.

The group operates opportunistically by exploiting unpatched software and has shifted to an affiliate model since early 2023.

Payments to initial access brokers range from $100 to $1 million.

The Healthcare and Public Health sector has been hit especially hard.

Recommended mitigations include timely patching of software and firmware, network segmentation and blocking untrusted access to remote services.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any assets including cryptocurrencies, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

The post 500 Organizations Breached as Medusa Ransomware Spreads Through Critical U.S. Infrastructure appeared first on The Daily Hodl.