500 Breaches Later, Medusa Ransomware Is Still Outrunning Its Warnings

Medusa ransomware https://www.pexels.com/photo/sculpture-of-medusa-on-a-stone-wall-5209697/

The Medusa ransomware-as-a-service variant, first identified in June 2021, has been The United States Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) released an advisory concerning Medusa ransomware on March 12th, 2025, warning of the more than 300 critical infrastructure victims since the discovery of the ransomware. The August 18th, 2026 update to the advisory, based on information from investigations through April 2026, adds the U.S. Department of Health and Human Services (HHS) as an authoring agency and reveals that the number of critical infrastructure victims has surpassed 500.

The advisory itself is a fairly standard rundown of the known tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with Medusa ransomware. The information is important on its own for defenders to protect against the ransomware, but the gap of only one year between the first warning and the update is another significant reason to pay attention.

How Medusa Built its Business

Medusa ransomware has been working at least since early 2023 on an affiliate model, where threat actors pay initial access brokers anywhere from $100 to $1 million USD per foothold. These customers are allowed different levels of trust and control depending on their experience and profitability, with the ransomware developers often retaining centralized control over ransom negotiations while decentralizing the management of the actual intrusion into the target system.

“The CISA advisory highlights a critical reality about Medusa’s evolution into a Ransomware-as-a-Service (RaaS) model: threat actors rarely break down the front door when they can buy key access from Initial Access Brokers (IABs) or exploit a third-party vendor,” says Matthieu Chan Tsin, Senior Vice President of Resiliency Services at Cowbell, a Pleasanton, California-based provider of cyber insurance for small to medium-sized enterprises (SMEs) and middle-market businesses. “With Medusa's campaigns targeting sector supply chains, attackers frequently leverage unpatched vulnerabilities in remote access protocols or compromise managed service providers to bypass primary defenses.”

The advisory outlines the living-off-the-land (LotL) techniques employed by Medusa actors, using tools including PowerShell, Windows Command Prompt, Windows Management Instrumentation, and legitimate remote monitoring and management (RMM) software, enabling attackers to go undetected as their victim count continues to climb. With these tactics, Medusa actors can achieve a wide range of goals, from network and filesystem enumeration and system information queries to lateral movement.

Exploitation Beyond Ransom Payment

Ransomware is often not as simple as the victim paying the ransom and the attacker returning their encrypted or stolen files. Medusa relies on a double extortion model, where the attacker both encrypts the data and threatens to leak or sell it. If the ransom is paid, there is no way for the victim to verify that the threat actors have actually removed the sensitive data from the site where they were offering it for sale.

The update August 2026 advisory notes that the FBI has documented a case of a second Medusa actor demanding repeat payment from a victim after the ransom had been paid. They claimed that the initial ransom had been stolen by the negotiator and requested that the victim send them half of the first payment again. This incident could indicate that the ransomware group is dysfunctional and incohesive, or it could potentially be a sign of triple extortion from Medusa actors. If the latter, the triple extortion precedent changes the calculations organizations must do when deciding whether to pay the ransom at all.

Commonly Targeted Sectors

The updated advisory notes that Medusa actors launch opportunistic attacks against vulnerable victims instead of directing their efforts solely toward specific organizations or sectors. While these attackers may not be deliberately aiming for particular types of organizations, the healthcare and public health (HPH) sector is frequently targeted by Medusa attacks, alongside sectors including the defense industrial base, government services, and financial services.

Repeated targeting of these sectors signals a widespread issue of resilience in critical infrastructure areas, rather than a simple gap in security coverage. The victims of Medusa are not targeted and susceptible due to a dearth of security tools, but due to deep structural vulnerabilities that require operational and cultural reform to address. This, combined with the highly critical nature of the systems and data that organizations in these sectors handle, demands coordinated action to remediate.

What the Advisory Gap Reveals

These two federal warnings bracketing only thirteen months of new information show a spike of 67% or more in the number of victims. Compared to the previous advisory, which covered four years of Medusa activity, there has been a significant rise in the cadence of Medusa attacks necessitating such a quick update.

While the growth in volume is notable, the mitigations put forth by the advisory are largely the same, encouraging organizations to patch vulnerabilities quickly, implement multi-factor authentication, and segment their networks to reduce potential damage. The new advisory leaves the question open of whether this development is an issue of defender adoption or attacker adaptation, as well as how critical sectors can meaningfully catch up to threat capabilities.

Author
  • Contributing Writer, Security Buzz
    PJ Bradley is a writer from southeast Michigan with a Bachelor's degree in history from Oakland University. She has a background in school-age care and experience tutoring college history students.