HIGHRansomware
Verified
United States

Medusa Ransomware Campaign Targets 40+ US School Districts

Tuesday, March 10, 2026 at 08:00 AM UTC·Source: FBI / CISA Joint Advisory

Updated: Wednesday, March 11, 2026 at 02:00 PM UTC

Executive Summary

Medusa ransomware group attacks over 40 US school districts via compromised RDP. Student and staff PII at risk. FBI issues sector-wide alert.

Analysis

Medusa ransomware has compromised over 40 US school districts through exposed or credential-stuffed RDP endpoints. Stolen data includes student records with grades, disciplinary actions, IEPs, and staff SSNs. FBI and CISA have issued a joint advisory with specific IOCs and mitigation guidance for the K-12 sector.

Timeline

Discovered
Mar 3, 2026
Exploitation Detected
Mar 3, 2026
Published
Mar 10, 2026
Source Attribution

Originally published by FBI / CISA Joint Advisory on Mar 10, 2026. Verified by: FBI, CISA, MS-ISAC.

Related Threats