HIGHRansomware
Verified
United States
Medusa Ransomware Campaign Targets 40+ US School Districts
Tuesday, March 10, 2026 at 08:00 AM UTC·Source: FBI / CISA Joint Advisory
Updated: Wednesday, March 11, 2026 at 02:00 PM UTC
Executive Summary
Medusa ransomware group attacks over 40 US school districts via compromised RDP. Student and staff PII at risk. FBI issues sector-wide alert.
Analysis
Medusa ransomware has compromised over 40 US school districts through exposed or credential-stuffed RDP endpoints. Stolen data includes student records with grades, disciplinary actions, IEPs, and staff SSNs. FBI and CISA have issued a joint advisory with specific IOCs and mitigation guidance for the K-12 sector.
Timeline
Discovered
Mar 3, 2026
Exploitation Detected
Mar 3, 2026
Published
Mar 10, 2026