Dormant High impact Ransomware Checked 20h ago

Medusa ransomware group has hit 500+ organizations

CISA, the FBI, and HHS updated a joint advisory again on August 18, 2026, warning that the Medusa ransomware gang has broken into more than 500 organizations, disabling security tools, stealing files, and encrypting networks. Victims span healthcare, education, legal, insurance, manufacturing, and technology companies. The new update adds detail on how Medusa affiliates buy network access from brokers and race to exploit newly disclosed software flaws, sometimes within a day of public disclosure.

Started
Mar 12, 2025
Latest activity
Aug 18, 2026
Attributed to
Medusa ransomware groupConfirmed
Where
United States
Sectors
Healthcare, Education, Manufacturing, Technology, Finance, Multiple sectors
Scale
more than 500 organizations across critical infrastructure sectors

Current status

A SOC Prime report published on September 9, 2026, reviews known Medusa attack behaviors but reports no new victims, arrests, or operational change.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

CISA, the FBI, and HHS jointly named the Medusa group in advisory AA25-071A.

Impact

Victim organizations have had files stolen and entire networks encrypted, with security tools disabled first to avoid detection. The updated advisory also flags that Medusa actors have exploited newer flaws in Fortra GoAnywhere and BeyondTrust software to break in.

What to do

Organizations, especially in healthcare and critical infrastructure, should apply the advisory's patching, MFA, and backup guidance rather than wait to be a target. Because Medusa actors can weaponize a newly disclosed vulnerability within about a day, patching quickly after vendor advisories matters more than usual.

Timeline

  1. Sep 9, 2026

    SOC Prime published a technical report reviewing Medusa attack behaviors and detection rules. It did not report new victims, arrests, or a change in the group's operations.

    Dormantsocprime.com
  2. Sep 8, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  3. Aug 20, 2026

    Security researchers reported a separate scam ring calling itself Ransom Busters that contacts ransomware victims, including some hit by double-extortion gangs like Medusa, falsely claiming to have hacked the criminals' servers and offering to delete stolen data for $20,000 to $60,000. Researchers say the group is itself made up of ransomware affiliates, not a legitimate recovery service, and this is a new extortion layer rather than a law enforcement or victim-side win against Medusa.

    Activetechradar.com
  4. Aug 18, 2026

    CISA, the FBI, and HHS updated the Medusa advisory again, still citing more than 500 confirmed victims and adding detail on how affiliates buy stolen network access and exploit newly disclosed flaws, including Fortra GoAnywhere and BeyondTrust vulnerabilities, often within 24 hours of disclosure.

    Activeic3.gov
  5. Aug 10, 2026

    Researchers reported that a former Medusa affiliate has moved on to a new ransomware strain called StormEncryptor, showing the Medusa affiliate ecosystem is still producing new spinoff threats.

    Activebleepingcomputer.com
  6. Aug 7, 2026

    CISA, the FBI, and HHS updated the advisory to reflect forensic findings through April 2026, raising the confirmed victim count past 500 organizations.

    Activecybersecuritynews.com
  7. Mar 12, 2025

    CISA, the FBI, and MS-ISAC first published the Medusa ransomware advisory after roughly 300 confirmed victims.

    Activecisa.gov

Sources

Related reports