An up to date joint cybersecurity advisory from the Federal Bureau of Investigation, Cybersecurity and Infrastructure Safety Company and Division of Well being and Human Companies mentioned the tally had exceeded 500 by April 2026. That represents a pointy improve from greater than 300 victims recognized by February 2025 and displays the enlargement of Medusa’s ransomware-as-a-service operation because it emerged in June 2021.
The affected sectors embody healthcare and public well being, the defence industrial base, essential manufacturing, authorities companies and services, info expertise and monetary companies. Organisations in training, authorized companies, insurance coverage and expertise have additionally been focused. Healthcare has turn into a very distinguished focus as a result of disruption can instantly have an effect on scientific companies whereas stolen medical info creates substantial leverage for extortion.
Medusa’s increasing attain has been accompanied by a big acceleration in its assault strategies. Investigations discovered that operators can exploit newly disclosed safety flaws inside 24 hours of particulars turning into public. Attackers have additionally been noticed exploiting vulnerabilities as a lot as per week earlier than public disclosure, sharply narrowing the window out there to defenders for deploying patches. Authorities have discovered no proof that Medusa itself develops zero-day vulnerabilities, suggesting operators get hold of exploit info from different sources or transfer shortly when new weaknesses turn into identified.
The group started as a comparatively closed ransomware operation earlier than adopting an affiliate mannequin round 2023. Builders now present ransomware infrastructure to exterior operators whereas retaining management over components of the legal enterprise, together with some ransom negotiations. Much less skilled associates might obtain larger operational help from the core group, permitting Medusa to increase its capability with out relying totally on a set crew of attackers.
Preliminary entry brokers have turn into an vital part of that construction. Medusa has marketed funds starting from about $100 to as a lot as $1 million for entry to compromised organisations, with the very best rewards supplied to brokers keen to work solely for the group. Shopping for established entry permits ransomware operators to bypass a few of the most tough levels of intrusion and transfer immediately in direction of privilege escalation, knowledge theft and encryption.
As soon as inside a community, Medusa actors use credential-stealing instruments, authentic distant monitoring functions and strategies that depend on software program already current throughout the sufferer’s setting. Distant-access merchandise noticed throughout assaults embody AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp and Splashtop. Utilizing authentic administration instruments could make malicious exercise more durable to tell apart from routine system administration.
The operation depends closely on double extortion. Attackers steal info earlier than encrypting methods, then threaten to publish or promote the fabric if fee is refused. Medusa’s leak website has displayed victims alongside countdown timers, ransom calls for and cryptocurrency fee info. Victims have additionally been supplied an extra day earlier than publication of stolen knowledge for a fee of $10,000.
Investigators have recognized indicators that the stress can lengthen additional. In a single case, a sufferer that had already paid was contacted by one other Medusa actor who claimed the unique negotiator had stolen the fee and demanded one other fee for the real decryptor. The episode raised the potential for triple extortion, though inner disputes or poor coordination throughout the ransomware community may additionally clarify the demand.
Ransom calls for are typically tailor-made to a goal’s publicly out there monetary info, whereas sooner fee can appeal to a diminished demand. Authorities say eradicating a sufferer from Medusa’s leak website after fee offers no assurance that stolen info has truly been destroyed.
The danger turned significantly seen after an assault on the College of Mississippi Medical Middle disrupted operations at a healthcare system that features Mississippi’s solely kids’s hospital, Degree I trauma centre and Degree IV neonatal intensive care unit. The incident pressured clinics to shut briefly and medical workers to depend on handbook processes whereas methods had been restored.
