Desk live·
ForensicPost
Ransomware/Advisory/File 25-0312

FBI, CISA and MS-ISAC Put Medusa Past 300 Critical Infrastructure Victims

On 12 March 2025 the FBI, CISA and MS-ISAC issued a joint advisory on Medusa, putting the operation past 300 victims across critical infrastructure sectors.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCritical infrastructure
ActorMedusa
S. Rosler11 min readConfidence: high3 sources reviewed

On 12 March 2025 the FBI, the Cybersecurity and Infrastructure Security Agency and the Multi-State Information Sharing and Analysis Center published a joint advisory on the Medusa ransomware-as-a-service operation, drawing on FBI investigations current to February 2025.

The advisory records the operation as active since June 2021 and as having affected over 300 victims across sectors including healthcare, insurance, technology, manufacturing and legal services.

Why This File Is Graded High And Most Are Not

The grading standard in this corpus turns on multiple independent sources or an official advisory. This is the second category, and it is the strongest form of it: three agencies, drawing on investigative casework rather than on telemetry from a company selling a product.

The corpus discounts vendor figures throughout — at 25-1102 it filed the case against a workforce-gap number produced by a certification body with an interest in it. An advisory built on investigations is not free of interest either, but the interest runs toward accuracy in a way a marketing figure’s does not.

What "Over 300 Victims" Means And Does Not

It is a count derived from investigations, which means it counts what came to the FBI’s attention. Organisations that paid quietly and never reported are outside it, and 25-0519 suggests that population is substantial where demands are small.

It is therefore a floor, in the sense the corpus set out at 25-0227: a figure that can only be an undercount. Those are the most useful figures in this database and there are very few of them.

Double And Triple Extortion

The advisory describes encryption plus threatened publication, and in some cases a further demand after payment. That last is worth naming plainly: it is a second extortion of a victim who has already complied.

The corpus recorded at 25-0215 that an undertaking not to return has no enforcement mechanism and no value. This is the same observation from the other side, in an official document.

How we reported this

Based on the joint advisory published by the FBI, CISA and MS-ISAC on 12 March 2025 and on published summaries of it, listed below. Graded high on the strength of the official advisory. The victim count is as stated in the advisory and reflects incidents known to the investigating agencies; it is not a count of all incidents. Corrections: corrections@forensicpost.com.

Sources
  1. #StopRansomware: Medusa ransomware (AA25-071A)CISA
  2. #StopRansomware: Medusa ransomware — joint cybersecurity advisoryIC3
  3. Response to CISA advisory AA25-071AAttackIQ
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary