# CISA says Medusa ransomware affected more than 500 critical-infrastructure organizations

_Wednesday, August 19, 2026 at 4:00 AM EDT · Security · Latest · Tier 1 — Major_

![CISA says Medusa ransomware affected more than 500 critical-infrastructure organizations — Primary](https://www.bleepstatic.com/content/hl-images/2026/08/19/Medusa-headpic.jpg)

CISA, the FBI and HHS said in a joint advisory that Medusa ransomware actors had affected more than 500 organizations across U.S. critical-infrastructure sectors as of April 2026. The agencies' March 2025 report had estimated more than 300 affected critical-infrastructure organizations. The advisory identifies healthcare, defense industrial base, critical manufacturing, government services, IT and financial services among the sectors affected, and recommends vulnerability mitigation, network segmentation and restrictions on untrusted access to internal remote services.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/)

---
Canonical: https://techandbusiness.org/newswire/weL1dD27rtB7M5iNV1AC0t
Retrieved: 2026-08-19T11:20:17.941Z
Publisher: Tech & Business (techandbusiness.org)
