Ransomware Now Shows Up in Nearly Half of All Breaches: A Survival Playbook for Lean Security Teams
Cyble reports 5,967 ransomware attacks in 2025, up 50%, accounting for nearly half of all tracked breaches.
Cyble's Global Cybersecurity Report 2025 documented 5,967 ransomware attacks, a 50% year-over-year jump. Against 6,046 data breaches and leaks recorded in the same period, ransomware accounted for 49.7% of the combined total. The blog lays out an incident response playbook for lean security teams facing this dominant threat.
Medusa ransomware gang has hit over 500 organizations, CISA warns
FBI, CISA, and HHS warn Medusa ransomware has hit over 500 organizations across critical infrastructure since June 2021, using phishing and unpatched flaws.
An updated joint advisory from CISA, FBI, and HHS states Medusa ransomware has affected more than 500 organizations, spanning healthcare, defense, manufacturing, government, IT, financial services, education, insurance, and legal sectors. Since early 2023 Medusa has operated a ransomware-as-a-service affiliate model and buys access from initial access brokers for $100 to $1 million. Affiliates gain entry via phishing and unpatched internet-facing software, exploiting newly disclosed flaws in ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust within 24 hours. The group runs double extortion, giving victims 48 hours before leak-site publication, with $10,000 in cryptocurrency buying a one-day delay.
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
CISA, FBI, and HHS updated their Medusa ransomware advisory, reporting over 500 victims and detailing the gang's access-broker and exploit tactics.
A joint advisory update from CISA, the FBI, and HHS expands the March 2025 Medusa guidance, drawing on a year of FBI investigations. The ransomware-as-a-service group's known victim tally grew from more than 300 to more than 500 between March 2025 and April 2026, with the Healthcare and Public Health sector frequently hit. Medusa pays access brokers $100 to $1 million, has exploited flaws such as Fortra GoAnywhere and BeyondTrust vulnerabilities, and leverages newly announced exploits within 24 hours, sometimes a week before public disclosure. The group uses living-off-the-land techniques, remote monitoring and management software, and RDP for lateral movement, and has been linked to actors including Microsoft-tracked Storm-1175 and North Korean hackers targeting healthcare.