Medusa ransomware group has hit 500+ organizations
CISA, the FBI, and HHS updated a joint advisory again on August 18, 2026, warning that the Medusa ransomware gang has broken into more than 500 organizations, disabling security tools, stealing files, and encrypting networks. Victims span healthcare, education, legal, insurance, manufacturing, and technology companies. The new update adds detail on how Medusa affiliates buy network access from brokers and race to exploit newly disclosed software flaws, sometimes within a day of public disclosure.
- Started
- Mar 12, 2025
- Latest activity
- Aug 18, 2026
- Attributed to
- Medusa ransomware groupConfirmed
- Where
- United States
- Sectors
- Healthcare, Education, Manufacturing, Technology, Finance, Multiple sectors
- Scale
- more than 500 organizations across critical infrastructure sectors
Current status
A SOC Prime report published on September 9, 2026, reviews known Medusa attack behaviors but reports no new victims, arrests, or operational change.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
CISA, the FBI, and HHS jointly named the Medusa group in advisory AA25-071A.
Impact
Victim organizations have had files stolen and entire networks encrypted, with security tools disabled first to avoid detection. The updated advisory also flags that Medusa actors have exploited newer flaws in Fortra GoAnywhere and BeyondTrust software to break in.
What to do
Organizations, especially in healthcare and critical infrastructure, should apply the advisory's patching, MFA, and backup guidance rather than wait to be a target. Because Medusa actors can weaponize a newly disclosed vulnerability within about a day, patching quickly after vendor advisories matters more than usual.
Timeline
-
Sep 9, 2026
SOC Prime published a technical report reviewing Medusa attack behaviors and detection rules. It did not report new victims, arrests, or a change in the group's operations.
Dormantsocprime.com -
Sep 8, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Aug 20, 2026
Security researchers reported a separate scam ring calling itself Ransom Busters that contacts ransomware victims, including some hit by double-extortion gangs like Medusa, falsely claiming to have hacked the criminals' servers and offering to delete stolen data for $20,000 to $60,000. Researchers say the group is itself made up of ransomware affiliates, not a legitimate recovery service, and this is a new extortion layer rather than a law enforcement or victim-side win against Medusa.
Activetechradar.com -
Aug 18, 2026
CISA, the FBI, and HHS updated the Medusa advisory again, still citing more than 500 confirmed victims and adding detail on how affiliates buy stolen network access and exploit newly disclosed flaws, including Fortra GoAnywhere and BeyondTrust vulnerabilities, often within 24 hours of disclosure.
Activeic3.gov -
Aug 10, 2026
Researchers reported that a former Medusa affiliate has moved on to a new ransomware strain called StormEncryptor, showing the Medusa affiliate ecosystem is still producing new spinoff threats.
Activebleepingcomputer.com -
Aug 7, 2026
CISA, the FBI, and HHS updated the advisory to reflect forensic findings through April 2026, raising the confirmed victim count past 500 organizations.
Activecybersecuritynews.com -
Mar 12, 2025
CISA, the FBI, and MS-ISAC first published the Medusa ransomware advisory after roughly 300 confirmed victims.
Activecisa.gov
Sources
- #StopRansomware: Medusa Ransomware CISA Aug 7, 2026
- Medusa ransomware steals data and locks networks Cyber Security News Aug 7, 2026
- #StopRansomware: Medusa Ransomware (Updated Aug. 18, 2026) IC3 (FBI) Aug 18, 2026
- CISA: Medusa ransomware hit over 500 critical infrastructure orgs BleepingComputer Aug 19, 2026
- Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware Infosecurity Magazine Aug 19, 2026
- Agencies issue update on Medusa ransomware activity American Hospital Association Aug 19, 2026
- HHS, FBI warn hospitals as Medusa ransomware tops 500 victims Becker's Hospital Review Aug 19, 2026 unverified
- New StormEncryptor ransomware used by former Medusa affiliate BleepingComputer Aug 10, 2026
- Medusa ransomware tallies hundreds of new victims, says updated advisory on group's tactics CyberScoop Aug 18, 2026
- Medusa Ransomware Hitting Healthcare Industry's Unpatched Software Vulnerabilities JD Supra Aug 20, 2026
- Medusa ransomware gang hits 500 critical infrastructure organisations, US agencies warn Computing Aug 19, 2026
- HHS, FBI warn hospitals as Medusa ransomware tops 500 victims Becker's Hospital Review Aug 19, 2026 unverified
- Medusa Ransomware Hitting Healthcare Industry's Unpatched Software Vulnerabilities JD Supra Aug 20, 2026
- CISA Updates Joint Advisory on Medusa Ransomware Homeland Security Today Aug 19, 2026 unverified
- Scammers pose as ransomware recovery agents, but just go on to steal more from victims TechRadar Aug 20, 2026
- Medusa Ransomware Scales to 500 Victims as Agencies Warn of Rapid Exploit Hunts WebProNews Aug 21, 2026
- CISA Updates Joint Advisory on Medusa Ransomware HSToday Aug 19, 2026 unverified
- Medusa Ransomware Hits Over 500 Organizations Worldwide, CISA Warns WebProNews Aug 26, 2026
- 500 Organizations Breached as Medusa Ransomware Spreads Through Critical U.S. Infrastructure Daily Hodl Sep 7, 2026
- Medusa Ransomware Detection: Key Behaviors Across Intrusions SOC Prime Sep 9, 2026
Related reports
- Medusa ransomware hits 500+ critical US sites Aug 18, 2026
- Medusa ransomware hits US critical infrastructure Aug 10, 2026
- Medusa ransomware steals data and locks networks Aug 7, 2026