CISA, the FBI, and HHS updated their joint advisory on Medusa ransomware on August 18, 2026, adding new details on the group's tactics against hospitals and other critical infrastructure organizations.

 

What happened

The Federal Bureau of Investigation, the Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services released an updated version of their joint advisory on Medusa ransomware. The agencies first published the advisory on March 12, 2025, and updated it on August 18, 2026, to include findings from FBI investigations conducted through April 2026. Medusa actors have impacted more than 500 victims across sectors including healthcare, education, legal services, insurance, technology, and manufacturing. The group operates a ransomware-as-a-service model and uses double extortion, encrypting victim data while threatening to leak it if the victim does not pay. HHS joined as a co-sealer on this update, contributing insight into Medusa's operations against the Healthcare and Public Health Sector. The FBI confirmed that Medusa is unrelated to the similarly named MedusaLocker ransomware or the Medusa mobile malware.

 

The backstory

The agencies originally published this advisory in March 2025 to share tactics and indicators of compromise identified as of February 2025. Since then, Medusa actors have continued operating and expanded their affiliate model.

This update follows a healthcare incident that the advisory notes. In late February 2026, a cyberattack knocked the University of Mississippi Medical Center offline for nine days. UMMC is Mississippi's largest hospital system and the only Level I trauma center, only children's hospital, and only organ transplant program in the state. Staff shifted to paper-based processes to keep the cancer infusion center and other units running while systems were down, and the hospital closed all 35 of its outpatient clinics during recovery. The Medusa gang later claimed responsibility for the attack and demanded an $800,000 ransom, threatening to leak stolen data if it went unpaid.

 

Going deeper

The update expands on how Medusa recruits initial access brokers, offering them between $100 and $1 million for access to victim networks. Medusa actors exploit unpatched vulnerabilities, including flaws in ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust, often within 24 hours of a vulnerability's public disclosure and sometimes before disclosure. Once inside a network, actors use legitimate tools such as Advanced IP Scanner, PowerShell, Mimikatz, and Volume Shadow Copy to move laterally, dump credentials, and steal data. The advisory also details newly observed tools, including the Nezha monitoring agent and MeshAgent, used to maintain backdoor access. Actors use Bandizip and Rclone to package and exfiltrate files before deploying their encryptor, gaze.exe, which disables backups and security services before encrypting files with AES-256.

 

What was said

"Medusa ransomware has been used by threat actors to conduct malicious activity against U.S. hospitals and health systems over the last several years," said John Riggi, AHA national advisor for cybersecurity and risk. "This year, Medusa claimed responsibility for a high-impact attack against a regionally important Level 1 trauma center, disrupting care delivery and posing a risk to patient and community safety. Once again, these attacks highlight the need for hospitals and health systems to strengthen cyber resiliency through enhanced defensive measures and clinical continuity procedures."

 

By the numbers

  • Medusa actors have impacted more than 500 victims as of April 2026.
  • Initial access brokers can earn between $100 and $1 million USD for providing network access.
  • Victims are given 48 hours to make contact after receiving a ransom note.
  • Victims can pay $10,000 in cryptocurrency to delay the leak-site countdown by one additional day.

In the know

Ransomware-as-a-service means the group behind Medusa develops the malware and licenses it to affiliates, who carry out attacks and share proceeds with the developers. Double extortion is when attackers first steal a copy of the victim's data, then threaten to publish it publicly if the ransom goes unpaid, even if the victim can restore systems from backups.

 

Why it matters

This update comes the same year Medusa claimed a high-impact attack on a regionally important Level 1 trauma center, an incident Riggi said disrupted care delivery and put patient and community safety at risk. Since Medusa actors move opportunistically against unpatched systems rather than targeting specific organizations, any hospital running vulnerable, internet-facing software is a potential target regardless of size or region. The group's use of legitimate remote access and monitoring tools already common in healthcare IT environments also makes its activity harder to distinguish from normal administrative traffic, making it harder for hospitals to monitor and restrict how those tools are used.

 

The bottom line

Hospitals and health systems should treat this update as a notice to revisit patching timelines, remote access controls, and clinical continuity plans. Medusa actors don't need to target healthcare specifically to disrupt it, they only need an unpatched, internet-facing system, which means the next victim could be a small community hospital or a major trauma center.

Related: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is ransomware-as-a-service?

It's a business model where ransomware developers lease their malware to affiliates, who carry out attacks and split the ransom proceeds with the developers.

 

How can healthcare organizations tell if they've been exploited through a known vulnerability?

Security teams identify this through vulnerability scanning, patch management logs, and by comparing exposed systems against published CVE lists.

 

What is the difference between ransomware and a data breach?

Ransomware encrypts and often steals data to extort payment, while a data breach refers more broadly to any unauthorized access or exposure of data, with or without extortion.