TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/CISA, FBI, and HHS Warn Medusa Ransomware Has Hit Over 500 Critical Infrastructure Orgs
News

CISA, FBI, and HHS Warn Medusa Ransomware Has Hit Over 500 Critical Infrastructure Orgs

A joint CISA, FBI, and HHS advisory update shows Medusa ransomware's critical infrastructure victim count nearly doubling since last year, with new detail on how the group evades detection using...

August 19, 2026 4 Min Read
43

The FBI, the Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services have updated a joint advisory on Medusa ransomware, reporting that the group and its affiliates have breached more than 500 critical infrastructure organizations in the United States, BleepingComputer reported. That is up from the more-than-300 figure the same advisory cited when CISA and the FBI first published it in March 2025.

Table Of Content

  • A Ransomware Business That Buys Its Way In
  • Living Off Tools Already Inside the Network
  • Why Healthcare Keeps Showing Up
  • What the Advisory Tells Defenders to Do

Tuesday’s update draws on FBI investigations conducted through April 2026, and it adds HHS as a co-sealing agency for the first time. The department joined specifically to detail how Medusa operates against hospitals and health systems, which the advisory describes as a frequent target alongside the Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services sectors. Victims outside those categories span the medical, education, legal, insurance, technology, and manufacturing industries, according to the advisory.

A Ransomware Business That Buys Its Way In

CISA and the FBI describe Medusa as a ransomware-as-a-service operation first identified in June 2021 that runs a double-extortion model: encrypt a victim’s data, then threaten to publish what was stolen if the ransom goes unpaid. Its operators recruit initial access brokers on criminal forums and marketplaces, paying them between $100 and $1 million for a foothold in a corporate network, with the higher end reserved for brokers willing to work exclusively for Medusa. Most brokers do not; the advisory notes they typically sell access to “multiple variants at the same time.”

Once a ransom demand is on the table, Medusa actors research a victim’s finances and size their demand against publicly posted revenue figures. They also discount for fast payment and sell time on the clock, charging $10,000 in cryptocurrency for each extra day before the deadline. The agencies say they have no way to verify that stolen data is actually deleted after a victim pays, and they continue to discourage paying at all.

Living Off Tools Already Inside the Network

The updated advisory, detailed by CyberScoop, adds new detail on how Medusa gets in and moves around once it is there. Affiliates favor internet-facing software such as Fortra’s GoAnywhere and BeyondTrust products, weaponizing newly disclosed vulnerabilities within 24 hours and, in some cases, using them up to a week before the flaws are publicly disclosed. The FBI says it found no indication that Medusa actors develop their own zero-day or n-day exploits; they instead obtain early access to exploit code from sources investigators could not identify.

Inside a compromised network, Medusa actors lean on remote monitoring and management software that already has a reason to be there, including AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop, which lets their activity blend in with normal IT support sessions. Investigators also documented the group placing tools like Rclone inside folders already excluded from Windows Defender scanning, and running an encoded command that excludes an entire system drive from scanning before copying in an encryptor. During credential harvesting, actors disable Defender through the local Group Policy Editor and re-enable it only once data exfiltration finishes. The advisory also describes actors setting the Active Directory Default Domain Policy to “Enabled, Enforced” specifically to override stricter Group Policy settings that would otherwise limit their movement.

For credential theft, Medusa actors copy the Active Directory database and registry hives out of a Volume Shadow Copy, then delete that copy to cover their tracks; the stolen material is used to forge Kerberos tickets that can compromise an entire domain. Before it finishes, the encryptor terminates services tied to backups, security tools, databases, and file sharing, and only then deletes shadow copies, a sequence built to remove a victim’s fastest paths to recovery.

Why Healthcare Keeps Showing Up

The advisory says Medusa targets organizations running unpatched software rather than picking specific sectors or companies, according to HealthSystemCIO’s reading of the update. HHS’s addition reflects that the Healthcare and Public Health sector ends up a frequent victim anyway, and the advisory does not report a separate healthcare-specific victim count within the overall 500-plus total.

The exposure gap has a structural explanation for hospitals in particular. Clinical environments often carry validated device software, vendor-controlled release cycles, and change windows built around patient care, all of which slow down patching compared with a typical enterprise environment. A ransomware operator that weaponizes disclosed vulnerabilities within 24 hours puts direct pressure on governance processes designed for a much slower threat.

The healthcare risk extends beyond Medusa’s own operators. Earlier this year, Microsoft detailed a group it tracks as Storm-1175 using Medusa ransomware in fast-moving intrusions, and researchers at Symantec and Carbon Black separately reported North Korean-linked hackers leaning on Medusa to target the health care sector.

What the Advisory Tells Defenders to Do

Beyond the standard patch-and-segment guidance, the update points to five specific checks security teams can act on immediately:

  • Assign an owner and a regular review cadence for the antivirus exclusion list, since Medusa actors have been caught hiding tools inside excluded folders.
  • Inventory every remote monitoring and management tool approved for use in the environment, then alert on unusual sessions from those specific tools rather than only on unfamiliar remote-access software.
  • Audit the Active Directory Default Domain Policy for any unexpected “Enabled, Enforced” settings that could be overriding stricter local controls.
  • Confirm backups are both immutable and stored offline, since the encryptor is built to terminate backup services and delete shadow copies before finishing.
  • Measure, in hours rather than days, how fast the organization can patch an internet-facing system once a vulnerability is disclosed.

HHS is asking healthcare and public health organizations to report incidents directly to the FBI or CISA, and the department is offering its own cyber incident support channel focused on limiting harm to patients during an active attack.

One clarifying note for anyone tracking the broader ransomware landscape: Medusa is a common name in cybercrime, and reporting on it has often been muddled by confusion with MedusaLocker, a separate and unrelated ransomware operation. The Medusa group covered in this advisory launched its own “Medusa Blog” leak site in 2023 and first drew wide media attention after claiming an attack on the Minneapolis Public Schools district that same year.

Tags:

CISACritical Infrastructurehealthcare-cybersecuritymedusa-ransomwareRansomware

Share

Cross-section of an oak log showing concentric growth rings, held up against a blue sky
Previous Post

How to Find the Commit That Broke Your Code With git bisect

Con artists run a three-cup shell game on a table in Berlin, luring passersby to guess which cup hides the ball
Next Post

Docker’s Latest Horror Story Turns a Patched Cursor Bug Into a Sandboxing Argument

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026