Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Medusa is a double-extortion ransomware-as-a-service operation active since 2021, documented by CISA/FBI as having affected over 300 victims, and distinct from the older MedusaLocker family and the Medusa Android trojan.
Medusa began around 2021 as a closed variant and later evolved into a RaaS. It conducts double-extortion attacks, exfiltrating data before encryption and threatening publication on its leak site. In March 2025 the FBI, CISA and MS-ISAC published advisory AA25-071A, documenting more than 300 victims across healthcare, education, legal, insurance, technology and manufacturing, based on activity investigated as recently as February 2025. FBI investigation stresses that this Medusa ransomware is unrelated to the older MedusaLocker family and to the Medusa mobile banking trojan.
Into 2026, activity attributed to Medusa deployment continued, including Microsoft reporting on Storm-1175 delivering Medusa in high-tempo operations against vulnerable web-facing systems.
Medusa's leak site has listed victims in Saudi Arabia, the UAE and Morocco among its international claims. These listings are extortion allegations and should be treated as claims, not confirmed breaches, unless independently verified.
+26 more relationships — see the relationships browser.