WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships (TLP:CLEAR) CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware

TLP:CLEAR

Author: Chase Snow

Created: Thursday, March 13, 2025 - 14:46

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

Summary: Yesterday, CISA—in partnership with the FBI and MS-ISAC—released a joint Cybersecurity Advisory, titled “#StopRansomware: Medusa Ransomware.” This advisory provides tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and detection methods associated with known Medusa ransomware activity.

Analyst Note: FBI and CISA urge organizations to act now to mitigate the threat posed by the Medusa ransomware gang. Since February 2025, the group attacked 300 organizations from a variety of critical infrastructure sectors. While no specific attack has been identified in the water and wastewater sector from Medusa ransomware, their propensity to attack critical infrastructure puts the sector at risk.

Immediate actions organizations can take to mitigate Medusa ransomware activity: 

  • Ensure operating systems, software, and firmware are patched and up to date.
  • Segment networks to restrict lateral movement.
  • Filter network traffic by preventing unknown or untrusted origins from accessing remote services.

WaterISAC encourages members and network defenders to review the advisory and implement its recommended mitigations to reduce the likelihood and impact of Medusa ransomware incidents.

Original Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a

Additional Reading:

  • Medusa Ransomware: FBI and CISA Urge Organizations to Act Now to Mitigate Threat
  • Medusa Ransomware Hits 40+ Victims in 2025, Demands $100K–$15M Ransom

Related WaterISAC PIRs: 6, 6.1, 7, 7.1, 12

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar