Medusa Ransomware Hits 500-Plus Victims as Agencies Warn of Rapid Exploitation

Federal agencies warn that Medusa ransomware has hit more than 500 victims and can exploit newly disclosed vulnerabilities within 24 hours of release.

Aug 20, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Department of Health and Human Services (HHS) have updated their joint advisory on Medusa ransomware, which has affected more than 500 victims worldwide since emerging in June 2021. Published Aug. 18, 2026, the update incorporates findings from FBI investigations through April 2026, up from the more than 300 victims reported in 2025.

According to the joint advisory, Medusa has affected organizations in the medical, education, legal, insurance, technology, and manufacturing industries. Healthcare has been a frequent target, although the group operates opportunistically rather than focusing exclusively on particular organizations or sectors.

Medusa shifted to an industrialized Ransomware-as-a-Service model in early 2023, purchasing access credentials from underground brokers for sums ranging from $100 to $1 million. The group also preys aggressively on unpatched software flaws in products from vendors such as ConnectWise ScreenConnect, Fortinet, Fortra, and BeyondTrust.

“Medusa actors leverage newly announced exploits within 24 hours,” the advisory states. The group has also used exploits up to a week before public vulnerability disclosure, although authorities found no indication that Medusa develops its own zero-day vulnerabilities. Once inside, operators use native tools such as PowerShell and legitimate remote-management software to evade detection and move laterally. They then deploy the gaze.exe encryptor, which terminates backup, security, database, communication, file-sharing, and website services before encrypting files.

The extortion trap

Medusa pairs file encryption with extortion, staging stolen records on a dark web leak site that displays countdowns to publication. Its ransom notes instruct victims to make contact within 48 hours, while victims can pay $10,000 in cryptocurrency to add one day to a leak-site countdown.

Federal authorities warned that paying yields no guarantee of recovery. The FBI documented at least one incident where a separate Medusa actor approached a paying victim, claiming the original negotiator stole the ransom, demanding an additional payment for the real decryption tool.

The 24-hour patching dilemma

Medusa’s sub-24-hour exploitation cycle breaks the traditional enterprise patching playbook. Most IT departments require days or weeks to evaluate patches for software conflicts before updating mission-critical systems. Rushing untested patches onto live servers introduces severe operational stability risks, but following standard testing windows leaves the door open to automated intrusion.

Advertisement

esecurityplanet.com/news/news-microsoft-august-2026-patch-tuesday/↗

Because Medusa relies on built-in administrative tools once a perimeter is breached, security teams cannot rely solely on fast patching. Defending against this operational tempo requires organizations to accept that perimeter breaches will occur, shifting priority toward strict network segmentation, application allowlisting, and isolating remote management software to halt lateral movement before encryption begins.

Federal authorities urge defenders to accelerate vulnerability mitigation on all internet-facing assets, enforce phishing-resistant multifactor authentication, isolate internal subnets, maintain immutable offline backups, and audit networks for unauthorized remote monitoring tools.

Read more: As Medusa expands its affiliate operations, ransomware attackers are also increasingly targeting managers and other business leaders whose authority and access can provide a path into critical systems.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.