incident-responsetrade-pressNewsThe Broadside2 min read

Medusa victim count jumps to 500 in updated CISA advisory

The group now pays access brokers up to $1 million and exploits newly announced vulnerabilities within 24 hours, sometimes before public disclosure.


TL;DR

CISA, FBI, and HHS updated their joint Medusa ransomware advisory Tuesday, expanding the victim count from more than 300 in March 2025 to more than 500 as of April 2026. The update details the group's affiliate model, with access-broker payments ranging from $100 to $1 million, and confirms Medusa actors routinely exploit newly announced vulnerabilities within 24 hours, sometimes up to a week before public disclosure. Most brokers work for multiple ransomware variants simultaneously. The advisory adds HHS as a co-sealer, reflecting the healthcare sector's status as a frequent target.

Medusa victim count jumps to 500 in updated CISA advisory
Editorial illustration · drawn by The Broadside

The updated advisory draws on FBI investigations conducted as recently as April 2026 and significantly expands the tactical picture. Medusa developers and affiliates operate a double-extortion model (encrypting victim data while threatening to release what they've exfiltrated) but the update makes clear the group doesn't develop its own zero-days. Instead, it obtains advanced access to exploits from unknown sources or sprints to weaponize public disclosures before patching cycles complete.

The economics are instructive. Access brokers commanding the top of the $100-to-$1-million range are those who work exclusively with Medusa. Most don't. The advisory notes that the majority of brokers sell access to multiple ransomware operations simultaneously, making the initial-access market a shared supply chain across variants. For defenders, that means a single unpatched Fortra GoAnywhere or BeyondTrust instance can feed several extortion campaigns in parallel.

What's new in the August 2026 update

The advisory adds detail on Medusa's use of Interactsh URLs for exploit verification, PowerShell obfuscation techniques, and command-and-control utilities. It also catalogs additional tools the group uses for network enumeration, persistence, and stealth, much of it living-off-the-land, leaning on legitimate remote monitoring tools like SimpleHelp and MeshAgent, plus built-in Windows utilities for lateral movement.

The healthcare angle

HHS joined as a co-sealer this round, and the advisory singles out the Healthcare and Public Health Sector as a frequent victim. That tracks: healthcare organizations run complex, often underpatched environments with high downtime intolerance, making them attractive targets for double-extortion operators. Earlier this year, Microsoft linked a Medusa affiliate (tracked as Storm-1175) to exploitation of a maximum-severity GoAnywhere MFT vulnerability discovered in September 2025, confirming the group's speed-to-exploit pattern.

The advisory recommends the standard #StopRansomware mitigations: patch operating systems and software within a risk-informed window, segment networks to contain lateral movement, and filter traffic to block untrusted origins from reaching remote services. For practitioners, the operational takeaway is narrower: if you're running internet-facing file-transfer or remote-access software, the clock between vulnerability disclosure and active exploitation is now measured in hours, not days.


Published ·Deep Fathom