Join our FREE personalized newsletter for news, trends, and insights that matter to everyone in America

Newsletter
New

Medusa Ransomware Scales To 500 Victims As Agencies Warn Of Rapid Exploit Hunts

Card image cap

Federal authorities delivered a sobering update this week. Medusa ransomware actors have now struck more than 500 organizations in critical infrastructure sectors. The toll marks a sharp rise from the more than 300 victims noted in an earlier alert.

The joint advisory, issued Aug. 18 by the Cybersecurity and Infrastructure Security Agency, FBI and Department of Health and Human Services, draws on investigations through April 2026. It paints a picture of a flexible ransomware-as-a-service operation that recruits outsiders for initial entry and moves with striking speed once inside. CISA advisory AA25-071A details the group’s tactics in plain terms.

Medusa first appeared in June 2021. It began as a closed shop run by a single team. By early 2023 the model shifted. Developers began selling access to affiliates, granting trust levels based on experience and results. “Medusa developers typically recruit initial access brokers in cybercriminal forums and marketplaces to obtain initial access to potential victims,” the advisory states. Payments range from $100 to $1 million, with top rates reserved for those working exclusively for the group.

But exclusivity proves rare. Most brokers juggle multiple ransomware variants at once. The arrangement lowers barriers for attackers while letting the core team focus on tooling and extortion.

The Human Cost in Healthcare

Healthcare bears the heaviest burden. The University of Mississippi Medical Center suffered a devastating breach in early 2026. The state’s only children’s hospital, Level I trauma center and organ transplant program went offline for nine days. Outpatient services halted. Staff resorted to paper records. Medusa demanded $800,000. The Record from Recorded Future News reported the episode generated widespread outrage.

John Riggi, the American Hospital Association’s national advisor for cybersecurity and risk, didn’t mince words. “Medusa ransomware has been used by threat actors to conduct malicious activity against U.S. hospitals and health systems over the last several years,” he told AHA News. “This year, Medusa claimed responsibility for a high-impact attack against a regionally important Level 1 trauma center, disrupting care delivery and posing a risk to patient and community safety.”

The pattern repeats. Defense contractors, manufacturers, government agencies, IT providers and financial institutions have all fallen victim. Education, insurance and law firms appear in the broader list. Opportunism drives targeting. Medusa actors scan for unpatched systems rather than fixating on one industry. Yet healthcare keeps surfacing as a favorite.

Speed defines the threat. The group pounces on newly announced vulnerabilities within 24 hours of disclosure. In some cases it deploys exploits up to a week before public notice. Infosecurity Magazine highlighted the tactic after reviewing the advisory. Microsoft researchers flagged the same behavior in related reporting cited by outlets covering the update.

Once inside, operators live off the land. They abuse legitimate remote monitoring tools. AnyDesk, Atera, ConnectWise, Splashtop and others facilitate lateral movement. Mimikatz dumps credentials. Rclone ships data to attacker-controlled servers. A process named gaze.exe eventually handles encryption, first killing backups and security services, then appending the .medusa extension to files.

The extortion follows a strict timetable. Victims receive 48 hours to respond to the ransom note. Silence triggers direct contact and publication on the Medusa leak site. A countdown begins. Pay $10,000 in cryptocurrency and buy another day. The double-extortion model—encrypt and threaten to leak—has become standard. Few agencies recommend paying. All urge reporting to the FBI’s Internet Crime Complaint Center.

Recommendations remain direct. Patch internet-facing systems on a risk-informed schedule. Segment networks to contain breaches. Filter traffic so untrusted sources cannot reach remote access services. These steps appear in every recent government alert on ransomware. Their repetition signals how seldom organizations follow them completely.

James Neilson, SVP global at OPSWAT, offered context in Computing. “Medusa ransomware group’s modus operandi is to seek privileged access and then move laterally to find valuable systems on which to deploy the ransomware. IT systems, internet connectivity, and transient devices remain major attack surfaces for ICS/OT infrastructure, and Medusa ransomware looks to exploit these.”

The advisory lists numerous vulnerabilities exploited in recent campaigns. ScreenConnect, Fortinet EMS, Fortra GoAnywhere and BeyondTrust flaws receive specific mention. The list grew in the August update, reflecting fresh FBI findings. Denis Calderone, chief technology officer at Suzu Labs, reacted to the speed of adoption. “They are not writing those zero-days themselves, they are buying them or racing the patch cycle, and that speed advantage is baked into the business model now,” he told SC Media.

Damon Small, board member at Xcape Inc., struck a broader note. Rapid exploitation of perimeter weaknesses creates enduring operational risk for healthcare and critical infrastructure providers. Unexpected downtime threatens services the public counts on daily.

Since the March 2025 advisory the victim count jumped by more than 200. That pace alarms defenders. Ransomware-as-a-service continues to mature. Initial access brokers commoditize entry. Core operators refine encryption and leak pressure. The combination scales attacks while diluting direct attribution.

Analysts tracking the space note Medusa remains distinct from MedusaLocker and unrelated mobile malware families. The clarification appears in every official release. It prevents confusion that could complicate incident response.

Organizations reading the latest warnings confront a familiar yet intensified challenge. The numbers keep climbing. Healthcare systems face both data loss and direct patient safety implications. Manufacturers risk production halts. Government agencies contend with service disruptions that ripple outward.

Defenders cannot simply wait for the next advisory. They must assume opportunistic actors already scan their internet-facing assets. They must verify segmentation actually limits movement. They must treat remote access tools as privileged pathways requiring strict controls. And they must prepare communication plans for when—not if—extortion demands arrive.

The Medusa campaign shows no signs of slowing. Its evolution from closed operation to affiliate marketplace mirrors broader ransomware trends. Speed of exploit adoption sets it apart. So does the willingness to hit hospitals and trauma centers without hesitation. Federal agencies have sounded the alarm. The question now is whether the organizations in the crosshairs will move fast enough to avoid joining the growing list of confirmed victims.