On August 18, 2026, the Cybersecurity & Infrastructure Security Agency, Federal Bureau of Investigation, and U.S. Department of Health & Human Services issued an update to a previous advisory to the health care industry warning against Medusa ransomware. The advisory provided tactics, techniques, and procedures as well as the indicators of compromise gathered to assist with response and remediation.
Medusa ransomware has been hitting the healthcare space particularly hard, but it’s also affecting the defense industry, critical manufacturing information technology, and financial services.
The advisory outlines how Medusa is a ransomware-as-a-service (RaaS) variant that was first identified in June 2021. Since its inception, Medusa developers and affiliates have hit over 500 victims, including “medical, education, legal, insurance, technology, and manufacturing.”
Although Medusa originally operated as a closed organization, since 2023 it has developed into an affiliate model, selling RaaS to affiliates that are paid different amounts depending on their experience and how effective they are in extorting victims. Medusa is a double extortion program, where they deploy ransomware to decrypt data, then extort victims for payment to decrypt and suppress publication of the data.
Medusa recruits access brokers in cybercriminal forums and marketplaces. The access brokers are the ones who attack the company through phishing campaigns, or exploit unpatched software vulnerabilities, including ScreenConnect, Fortinet, Fortra, and BeyondTrust. They pay the access brokers between $100 and $1 million to break into the company and sell that access to Medusa operators. They leverage new vulnerabilities within 24 hours and sometimes before they are announced. Once in, the access brokers use legitimate tools to cover their tracks to give them time to sell their wares to Medusa (and other ransomware gangs). Medusa then uses legitimate remote monitoring software to evade detection to exfiltrate data, deploy the ransomware, and extort the victim.
The advisory lists the indicators of compromise that companies should review and block. It also provides common remediation, including eviction countermeasures, and mitigations, which should be applied as soon as possible.
The advisory reinforces how important it is to continue internal phishing tests, employee training, and patching programs as priorities to help avoid becoming a victim.