Medusa ransomware has now hit more than 500 organizations across critical infrastructure sectors, according to an updated joint advisory from the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Department of Health and Human Services (HHS) published August 18, 2026. The update, which folds in FBI investigative findings through April 2026, adds HHS as a co-sealing agency for the first time, a signal that healthcare has become one of the group’s most frequent targets.
A count that keeps climbing
Medusa first surfaced as a closed ransomware-as-a-service (RaaS) operation in June 2021, according to the advisory. Since early 2023 it has run an affiliate model, selling access to outside operators who are vetted and granted escalating trust based on experience and how much revenue they bring in. That shift from a tightly controlled crew to a franchised operation is the same pattern behind the growth curves of other major RaaS brands, and it shows up in the numbers: the advisory’s prior version, published in March 2025, put the toll at more than 300 critical infrastructure victims. Seventeen months later, that figure has grown by two thirds.
The victims span Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services, plus organizations in education, legal, insurance, and general manufacturing. HHS’s addition as a co-sealing agency reflects its insight into Medusa’s operations against the Healthcare and Public Health Sector, which the advisory calls a frequent target even though Medusa affiliates are opportunistic rather than sector-specific in how they pick victims.
Speed is the affiliate model’s real weapon
The advisory’s most operationally useful finding is about timing, not tooling. Medusa actors typically do not develop their own zero-day or n-day exploits. Instead they buy or otherwise obtain working exploits and move on them fast: the agencies say affiliates have leveraged newly disclosed vulnerabilities within 24 hours of publication, and in some cases have used exploits up to a week before the underlying flaw was even publicly disclosed. Affiliates pay initial access brokers between $100 and $1 million for a foothold, and the advisory notes that most brokers work across multiple ransomware brands at once rather than exclusively for Medusa, which is one reason a single broker’s access can surface in several unrelated ransomware cases.
Once inside, affiliates favor commercial remote monitoring and management tools already trusted on the network, alongside living-off-the-land techniques that blend into normal administrative activity, making the intrusion harder to distinguish from legitimate IT work until data starts moving. The advisory documents a double-extortion model: files are encrypted and a copy of the data is exfiltrated, with the threat of publication used as leverage separate from the ransom demand for decryption. Victims who do not respond within 48 hours are contacted directly by phone or email, and the advisory records at least one case in which a victim who had already paid was contacted again by a second Medusa actor claiming the first negotiator had stolen the payment, a detail the agencies flag as a possible sign of dysfunction inside the affiliate structure.
A fingerprint defenders can actually watch for
One detail in the advisory gives defenders something concrete to hunt rather than just a patching deadline. Medusa actors use Interactsh, an open-source out-of-band service, to confirm an exploit worked before they proceed further into a network: the compromised host generates a callback to a domain ending in oast.site, oast.pro, or oast.fun, with a subdomain that encodes which victim was hit. That callback happens before encryption, before exfiltration, and often before an affiliate has decided how deep to go, which makes it one of the earliest possible detection points in the entire intrusion chain. Egress monitoring rules that flag outbound requests to those three domains, or to out-of-band interaction services generally from hosts that have no legitimate reason to reach one, catch the affiliate at the exact moment it is verifying access rather than after the fact.
What it means for the security leader
The 24-hour exploitation window is the number that should change budget conversations. If an affiliate model can weaponize a new CVE inside a day of disclosure, the emergency-patch process that most organizations reserve for confirmed active exploitation needs to start at disclosure, not at confirmation. CyberTech has tracked this exact compression before, where a vCenter flaw went from patch to ransomware weapon inside days, and Medusa’s advisory suggests that timeline is now closer to the norm for opportunistic RaaS affiliates than the exception.
The advisory’s inclusion of legitimate RMM tools as a preferred intrusion vector also argues for asset-level allowlisting rather than blanket trust in any tool with a valid code signature. Security teams that already maintain a baseline of which remote access tools are authorized on which systems have a real detection edge here, because unexpected RMM activity is one of the advisory’s clearest indicators of compromise, more reliable than the encryption event that only appears once it is too late.
What to do
The authoring agencies’ mitigations map to a short, concrete list: patch known vulnerabilities on a risk-informed schedule that assumes single-digit-day exploitation windows rather than the multi-week cycles many patch programs still run on; segment networks so a single compromised device cannot reach the whole environment; require phishing-resistant multi-factor authentication, since credential theft via phishing remains the group’s primary entry method; and maintain offline, tested backups, since Medusa’s double-extortion model means recovery capability determines leverage in a negotiation the agencies advise against entering in the first place. The full advisory also carries indicators of compromise that SOC teams tracking other ransomware advisories this month should cross-reference, since initial-access-broker overlap between RaaS brands means Medusa indicators can surface in unrelated incident response engagements.
The agencies continue to discourage paying the ransom, noting that payment does not guarantee file recovery and may fund further attacks. Organizations that experience a Medusa intrusion are asked to report it to the FBI’s Internet Crime Complaint Center or CISA, and Healthcare and Public Health Sector organizations specifically can reach HHS’s cyber incident support line for help managing patient-impact risk during an active incident.

