Illustrative image generated with AI
Medusa Ransomware Victims Surpass 500: Healthcare and Critical Infrastructure in the Crosshairs
CISA and FBI report Medusa ransomware has over 500 victims, with attacks on healthcare and critical infrastructure, exploiting vulnerabilities rapidly.
Text generated by artificial intelligence, published without human review. AI transparency
CISA and FBI Document the Surge in Attacks
Medusa ransomware affiliates had targeted more than 500 victims by April 2026. The figure comes from an update to the advisory published by CISA and the FBI, which was initially released in March 2025.
In 2025, the U.S. agencies had identified approximately 300 targeted organizations. The increase therefore exceeds 200 victims, with a significant presence in sectors classified as critical infrastructure.
Medusa has not limited its activities to a single industry. Targets have included healthcare facilities, U.S. municipalities, and international organizations. The group has been active since 2021 and has adopted a strategy built around operational and financial pressure on victims.
The available material does not indicate whether Medusa has been added to CISA’s KEV catalog, nor does it provide an inclusion date or mitigation deadline. It also contains no CVE identifiers associated with the exploits described in the advisory.
The Attack on Mississippi’s Children’s Hospital
In April, Medusa disrupted operations at the University of Mississippi Medical Center. The facility is described as Mississippi’s only children’s hospital, the state’s only Level I trauma center, and its only Level IV neonatal intensive care unit.
The hospital also houses the state’s only organ transplant program. An attack against an organization with this profile can therefore affect not only IT systems, but also the delivery of essential healthcare services.
The incident highlights the concrete risks created by Medusa’s focus on the healthcare sector. An intrusion can disable administrative systems, disrupt clinical workflows, and complicate the management of emergencies, admissions, and specialized procedures.
The overall number of victims and the selection of critical targets increase the significance of the campaign. However, it is not known how many of the more than 500 organizations paid a ransom or how much data was stolen.
Exploiting Vulnerabilities at Increasing Speed
The advisory describes an exceptionally rapid adoption of exploits. Affiliates may exploit a newly disclosed vulnerability within 24 hours of its public disclosure.
In some cases, operators were reportedly observed using exploits up to a week before the vulnerability was officially published. This does not demonstrate that Medusa independently develops zero-day or N-day exploits.
According to CISA and the FBI, the most plausible explanation is that the group obtains early access to advanced exploits from undisclosed sources or rapidly deploys publicly available tools before organizations can apply the relevant patches.
Microsoft described the same dynamic in a report published on April 6, 2026, concerning ransomware operations conducted by Storm-1175 on behalf of Medusa. The targets were Internet-facing assets that lacked available updates.
The risk window can therefore shrink to just a few hours. An unpatched web-facing system can become an entry point before security teams have completed their assessment of a newly disclosed vulnerability.
A Multi-Level Organization and Dual Financial Pressure
Medusa began as a closed ransomware group but shifted to an affiliate-based model in 2023. Its developers provide the ransomware and assign different access levels based on operators’ experience and financial performance.
For less experienced affiliates, negotiations with victims may also remain under the developers’ control. Recruitment takes place on criminal forums, and the group reportedly offered up to $1 million to initial access brokers willing to work exclusively with it.
Before targeting an organization, operators often conduct reconnaissance. Ransom demands may be calibrated to the victim’s publicly reported revenue, turning financial information into a tool for increasing the ransom amount.
Negotiations may include discounts for victims who pay quickly. Conversely, extending the deadline for publishing stolen data by just one day may cost $10,000.
When a victim pays, Medusa removes the information from its leak site. CISA and the FBI stress, however, that there is no way to verify whether the data has actually been deleted. Payment therefore does not guarantee the destruction of copies or necessarily prevent further misuse.
The advisory also cites an incident potentially consistent with triple extortion or an internal dispute. One operator allegedly claimed that the negotiator had stolen the ransom already paid, then demanded half the amount in exchange for delivering the “real decryptor.”
The incident could point to a duplicate demand accompanied by a renewed threat, or to poor coordination among affiliates. It is not known which interpretation is correct.
Legitimate Tools Used to Conceal the Compromise
After gaining initial access, operators steal credentials and use legitimate software for monitoring and remote administration. The use of tools commonly found in corporate environments can make it harder to distinguish malicious activity from administrators’ actions.
The FBI observed the use of the following products:
- AnyDesk;
- Atera;
- ConnectWise;
- eHorus;
- N-able;
- BeyondTrust;
- SimpleHelp;
- Splashtop.
The versions used have not been disclosed. Organizations should therefore assess not only whether these programs are present, but also who installed them, which accounts use them, and which systems they connect to.
According to SafeBreach, actors linked to Medusa are dramatically compressing intrusion timelines. Only a few hours may pass between initial access and data exfiltration, rather than several days.
This reduces the time available to detect an attack before encryption or data publication occurs. Credential theft, remote access, and rapid data transfer should be analyzed as a potential single sequence, not as independent events.
Operational Priorities for Organizations
The first measure is to promptly patch Internet-facing assets, especially when a new vulnerability is disclosed. In Medusa’s case, delaying an update may leave an exploitable window open for as little as 24 hours.
Security teams should also:
- monitor for anomalous access and signs of credential theft or reuse;
- identify unauthorized installations of the remote access software listed by the agencies;
- investigate unexpected connections originating from or directed to remote administration tools;
- review web-facing systems that lack available fixes;
- look for a rapid sequence involving initial access, lateral movement, and exfiltration;
- preserve events useful for forensic analysis and post-compromise detection.
No new victims appear to have been added to the leak site since April. The slowdown may reflect increased investigative attention following the attack on the University of Mississippi Medical Center, but it does not support the conclusion that Medusa’s activities have ended.
Sources
This article is an original reworking based on the sources below.
