On 12 March 2025 the FBI, the Cybersecurity and Infrastructure Security Agency and the Multi-State Information Sharing and Analysis Center published a joint advisory on the Medusa ransomware-as-a-service operation, drawing on FBI investigations current to February 2025.
The advisory records the operation as active since June 2021 and as having affected over 300 victims across sectors including healthcare, insurance, technology, manufacturing and legal services.
Why This File Is Graded High And Most Are Not
The grading standard in this corpus turns on multiple independent sources or an official advisory. This is the second category, and it is the strongest form of it: three agencies, drawing on investigative casework rather than on telemetry from a company selling a product.
The corpus discounts vendor figures throughout — at 25-1102 it filed the case against a workforce-gap number produced by a certification body with an interest in it. An advisory built on investigations is not free of interest either, but the interest runs toward accuracy in a way a marketing figure’s does not.
What "Over 300 Victims" Means And Does Not
It is a count derived from investigations, which means it counts what came to the FBI’s attention. Organisations that paid quietly and never reported are outside it, and 25-0519 suggests that population is substantial where demands are small.
It is therefore a floor, in the sense the corpus set out at 25-0227: a figure that can only be an undercount. Those are the most useful figures in this database and there are very few of them.
Double And Triple Extortion
The advisory describes encryption plus threatened publication, and in some cases a further demand after payment. That last is worth naming plainly: it is a second extortion of a victim who has already complied.
The corpus recorded at 25-0215 that an undertaking not to return has no enforcement mechanism and no value. This is the same observation from the other side, in an official document.
Based on the joint advisory published by the FBI, CISA and MS-ISAC on 12 March 2025 and on published summaries of it, listed below. Graded high on the strength of the official advisory. The victim count is as stated in the advisory and reflects incidents known to the investigating agencies; it is not a count of all incidents. Corrections: corrections@forensicpost.com.