Stay up to date with notifications from The Independent

Notifications can be managed in browser preferences.

Cybersecurity officials warn against potentially costly Medusa ransomware attacks

The FBI and the U.S. Cybersecurity and Infrastructure Security Agency are warning email users against a dangerous ransomware scheme

Sarah Parvini
Saturday 15 March 2025 14:04 EDT
FBI-Ransomware-Warning
FBI-Ransomware-Warning (Copyright 2021 The Associated Press. All rights reserved.)

The FBI and the U.S. Cybersecurity and Infrastructure Security Agency are warning against a dangerous ransomware scheme.

In an advisory posted earlier this week, government officials warned that a ransomware-as-a-service software called Medusa, which has launched ransomware attacks since 2021, has recently affected hundreds of people. Medusa uses phishing campaigns as its main method for stealing victims' credentials, according to CISA.

To protect against the ransomware, officials recommended patching operating systems, software and firmware, in addition to using multifactor authentication for all services such as email and VPNs. Experts also recommended using long passwords, and warned against frequently recurring password changes because they can weaken security.

Medusa developers and affiliates ā€” called ā€œMedusa actorsā€ ā€” use a double extortion model, where they ā€œencrypt victim data and threaten to publicly release exfiltrated data if a ransom is not paid,ā€ the advisory said. Medusa operates a data-leak site that shows victims alongside countdowns to the release of information.

ā€œRansom demands are posted on the site, with direct hyperlinks to Medusa affiliated cryptocurrency wallets,ā€ the advisory said. ā€œAt this stage, Medusa concurrently advertises sale of the data to interested parties before the countdown timer ends. Victims can additionally pay $10,000 USD in cryptocurrency to add a day to the countdown timer.ā€

Since February, Medusa developers and affiliates have hit more than 300 victims across industries, including the medical, education, legal, insurance, technology and manufacturing sectors, CISA said.

Thank you for registering

Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in