Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

BumRushDaShow

(149,992 posts)
Sat Mar 15, 2025, 08:30 PM Mar 15

Cybersecurity officials warn against potentially costly Medusa ransomware attacks

Source: AP

Updated 2:04 PM EDT, March 15, 2025


LOS ANGELES (AP) — The FBI and the U.S. Cybersecurity and Infrastructure Security Agency are warning against a dangerous ransomware scheme.

In an advisory posted earlier this week, government officials warned that a ransomware-as-a-service software called Medusa, which has launched ransomware attacks since 2021, has recently affected hundreds of people. Medusa uses phishing campaigns as its main method for stealing victims’ credentials, according to CISA.

To protect against the ransomware, officials recommended patching operating systems, software and firmware, in addition to using multifactor authentication for all services such as email and VPNs. Experts also recommended using long passwords, and warned against frequently recurring password changes because they can weaken security.

Medusa developers and affiliates — called “Medusa actors” — use a double extortion model, where they “encrypt victim data and threaten to publicly release exfiltrated data if a ransom is not paid,” the advisory said. Medusa operates a data-leak site that shows victims alongside countdowns to the release of information.

Read more: https://apnews.com/article/fbi-cisa-gmail-outlook-cyber-security-email-6ed749556967654ff41a629a230973e6



Link to CISA ALERT - CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware
5 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Cybersecurity officials warn against potentially costly Medusa ransomware attacks (Original Post) BumRushDaShow Mar 15 OP
It's possible because of the inept meddling of government agencies' files, no_hypocrisy Mar 15 #1
Who are you kidding dweller Mar 15 #2
Watch for a huge increase in every kind of scam... Think. Again. Mar 15 #3
Musk's hacker boys are also a threat to America's cybersecurity IronLionZion Mar 15 #4
Message auto-removed Name removed Mar 25 #5

no_hypocrisy

(50,949 posts)
1. It's possible because of the inept meddling of government agencies' files,
Sat Mar 15, 2025, 08:34 PM
Mar 15

it's possible for Medusa, for example, to get into Social Security payment programs, and hold that hostage.

Think. Again.

(22,330 posts)
3. Watch for a huge increase in every kind of scam...
Sat Mar 15, 2025, 09:20 PM
Mar 15

...now that scammers know the U.S. government is cutting back on all safeguards and prosecutions.

IronLionZion

(48,280 posts)
4. Musk's hacker boys are also a threat to America's cybersecurity
Sat Mar 15, 2025, 10:08 PM
Mar 15

since nobody know what they are up to. DOGE will respond by firing more people in charge of cybersecurity.

Response to BumRushDaShow (Original post)

Latest Discussions»Latest Breaking News»Cybersecurity officials w...