medusa Unknown
First seen:
14/02/2026 11:26
Last Attack:
14/02/2026
5
Total Victims
0
Victims (30d)
Details
Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.
Leak Site
Onion URL:
http://medusakxxtp3uo7vusntvubnytaph4d3amxivbggl3hnhpk2nmus34yd.onion
Victims by Country
🇺🇸
United States
4
🇮🇹
Italy
1
Ransomware Victims 5
| Victim | Country | Sector | Discovered |
|---|---|---|---|
| Balloons Everywhere | 🇺🇸 US | Consumer Services |
14/02/2026 11:27 14/02/2026 |
| South Hays Fire Department | 🇺🇸 US | Public Sector |
14/02/2026 11:27 14/02/2026 |
| Comune di Battipaglia | 🇮🇹 IT | Public Sector |
14/02/2026 11:27 14/02/2026 |
| Grandview Family Medicine | 🇺🇸 US | Healthcare |
14/02/2026 11:27 14/02/2026 |
| MESA Products | 🇺🇸 US | Manufacturing |
14/02/2026 11:26 14/02/2026 |
Metadata
Slug:
medusa
Created: 14/01/2026 08:19
Updated: 28/06/2026 16:02