CISA, FBI, and HHS Warn Medusa Ransomware Has Hit Over 500 Critical Infrastructure Orgs
A joint CISA, FBI, and HHS advisory update shows Medusa ransomware's critical infrastructure victim count nearly doubling since last year, with new detail on how the group evades detection using...
The FBI, the Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services have updated a joint advisory on Medusa ransomware, reporting that the group and its affiliates have breached more than 500 critical infrastructure organizations in the United States, BleepingComputer reported. That is up from the more-than-300 figure the same advisory cited when CISA and the FBI first published it in March 2025.
Table Of Content
Tuesday’s update draws on FBI investigations conducted through April 2026, and it adds HHS as a co-sealing agency for the first time. The department joined specifically to detail how Medusa operates against hospitals and health systems, which the advisory describes as a frequent target alongside the Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services sectors. Victims outside those categories span the medical, education, legal, insurance, technology, and manufacturing industries, according to the advisory.
A Ransomware Business That Buys Its Way In
CISA and the FBI describe Medusa as a ransomware-as-a-service operation first identified in June 2021 that runs a double-extortion model: encrypt a victim’s data, then threaten to publish what was stolen if the ransom goes unpaid. Its operators recruit initial access brokers on criminal forums and marketplaces, paying them between $100 and $1 million for a foothold in a corporate network, with the higher end reserved for brokers willing to work exclusively for Medusa. Most brokers do not; the advisory notes they typically sell access to “multiple variants at the same time.”
Once a ransom demand is on the table, Medusa actors research a victim’s finances and size their demand against publicly posted revenue figures. They also discount for fast payment and sell time on the clock, charging $10,000 in cryptocurrency for each extra day before the deadline. The agencies say they have no way to verify that stolen data is actually deleted after a victim pays, and they continue to discourage paying at all.
Living Off Tools Already Inside the Network
The updated advisory, detailed by CyberScoop, adds new detail on how Medusa gets in and moves around once it is there. Affiliates favor internet-facing software such as Fortra’s GoAnywhere and BeyondTrust products, weaponizing newly disclosed vulnerabilities within 24 hours and, in some cases, using them up to a week before the flaws are publicly disclosed. The FBI says it found no indication that Medusa actors develop their own zero-day or n-day exploits; they instead obtain early access to exploit code from sources investigators could not identify.
Inside a compromised network, Medusa actors lean on remote monitoring and management software that already has a reason to be there, including AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop, which lets their activity blend in with normal IT support sessions. Investigators also documented the group placing tools like Rclone inside folders already excluded from Windows Defender scanning, and running an encoded command that excludes an entire system drive from scanning before copying in an encryptor. During credential harvesting, actors disable Defender through the local Group Policy Editor and re-enable it only once data exfiltration finishes. The advisory also describes actors setting the Active Directory Default Domain Policy to “Enabled, Enforced” specifically to override stricter Group Policy settings that would otherwise limit their movement.
For credential theft, Medusa actors copy the Active Directory database and registry hives out of a Volume Shadow Copy, then delete that copy to cover their tracks; the stolen material is used to forge Kerberos tickets that can compromise an entire domain. Before it finishes, the encryptor terminates services tied to backups, security tools, databases, and file sharing, and only then deletes shadow copies, a sequence built to remove a victim’s fastest paths to recovery.
Why Healthcare Keeps Showing Up
The advisory says Medusa targets organizations running unpatched software rather than picking specific sectors or companies, according to HealthSystemCIO’s reading of the update. HHS’s addition reflects that the Healthcare and Public Health sector ends up a frequent victim anyway, and the advisory does not report a separate healthcare-specific victim count within the overall 500-plus total.
The exposure gap has a structural explanation for hospitals in particular. Clinical environments often carry validated device software, vendor-controlled release cycles, and change windows built around patient care, all of which slow down patching compared with a typical enterprise environment. A ransomware operator that weaponizes disclosed vulnerabilities within 24 hours puts direct pressure on governance processes designed for a much slower threat.
The healthcare risk extends beyond Medusa’s own operators. Earlier this year, Microsoft detailed a group it tracks as Storm-1175 using Medusa ransomware in fast-moving intrusions, and researchers at Symantec and Carbon Black separately reported North Korean-linked hackers leaning on Medusa to target the health care sector.
What the Advisory Tells Defenders to Do
Beyond the standard patch-and-segment guidance, the update points to five specific checks security teams can act on immediately:
- Assign an owner and a regular review cadence for the antivirus exclusion list, since Medusa actors have been caught hiding tools inside excluded folders.
- Inventory every remote monitoring and management tool approved for use in the environment, then alert on unusual sessions from those specific tools rather than only on unfamiliar remote-access software.
- Audit the Active Directory Default Domain Policy for any unexpected “Enabled, Enforced” settings that could be overriding stricter local controls.
- Confirm backups are both immutable and stored offline, since the encryptor is built to terminate backup services and delete shadow copies before finishing.
- Measure, in hours rather than days, how fast the organization can patch an internet-facing system once a vulnerability is disclosed.
HHS is asking healthcare and public health organizations to report incidents directly to the FBI or CISA, and the department is offering its own cyber incident support channel focused on limiting harm to patients during an active attack.
One clarifying note for anyone tracking the broader ransomware landscape: Medusa is a common name in cybercrime, and reporting on it has often been muddled by confusion with MedusaLocker, a separate and unrelated ransomware operation. The Medusa group covered in this advisory launched its own “Medusa Blog” leak site in 2023 and first drew wide media attention after claiming an attack on the Minneapolis Public Schools district that same year.








No Comment! Be the first one.