The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Department of Health and Human Services (HHS) have updated their joint advisory on Medusa ransomware, which has affected more than 500 victims worldwide since emerging in June 2021. Published Aug. 18, 2026, the update incorporates findings from FBI investigations through April 2026, up from the more than 300 victims reported in 2025.
According to the joint advisory, Medusa has affected organizations in the medical, education, legal, insurance, technology, and manufacturing industries. Healthcare has been a frequent target, although the group operates opportunistically rather than focusing exclusively on particular organizations or sectors.
Medusa shifted to an industrialized Ransomware-as-a-Service model in early 2023, purchasing access credentials from underground brokers for sums ranging from $100 to $1 million. The group also preys aggressively on unpatched software flaws in products from vendors such as ConnectWise ScreenConnect, Fortinet, Fortra, and BeyondTrust.
“Medusa actors leverage newly announced exploits within 24 hours,” the advisory states. The group has also used exploits up to a week before public vulnerability disclosure, although authorities found no indication that Medusa develops its own zero-day vulnerabilities. Once inside, operators use native tools such as PowerShell and legitimate remote-management software to evade detection and move laterally. They then deploy the gaze.exe encryptor, which terminates backup, security, database, communication, file-sharing, and website services before encrypting files.
The extortion trap
Medusa pairs file encryption with extortion, staging stolen records on a dark web leak site that displays countdowns to publication. Its ransom notes instruct victims to make contact within 48 hours, while victims can pay $10,000 in cryptocurrency to add one day to a leak-site countdown.
Federal authorities warned that paying yields no guarantee of recovery. The FBI documented at least one incident where a separate Medusa actor approached a paying victim, claiming the original negotiator stole the ransom, demanding an additional payment for the real decryption tool.
The 24-hour patching dilemma
Medusa’s sub-24-hour exploitation cycle breaks the traditional enterprise patching playbook. Most IT departments require days or weeks to evaluate patches for software conflicts before updating mission-critical systems. Rushing untested patches onto live servers introduces severe operational stability risks, but following standard testing windows leaves the door open to automated intrusion.
esecurityplanet.com/news/news-microsoft-august-2026-patch-tuesday/↗
Because Medusa relies on built-in administrative tools once a perimeter is breached, security teams cannot rely solely on fast patching. Defending against this operational tempo requires organizations to accept that perimeter breaches will occur, shifting priority toward strict network segmentation, application allowlisting, and isolating remote management software to halt lateral movement before encryption begins.
Recommended countermeasures
Federal authorities urge defenders to accelerate vulnerability mitigation on all internet-facing assets, enforce phishing-resistant multifactor authentication, isolate internal subnets, maintain immutable offline backups, and audit networks for unauthorized remote monitoring tools.
Read more: As Medusa expands its affiliate operations, ransomware attackers are also increasingly targeting managers and other business leaders whose authority and access can provide a path into critical systems.





