CISA, the FBI, and HHS issued an updated joint advisory warning that Medusa ransomware operators have compromised more than 500 organizations as of April 2026, with heavy targeting of critical infrastructure and especially healthcare and public health entities. The agencies said the group evolved from a closed operation into a ransomware-as-a-service model in 2023, using double extortion by stealing data before encrypting systems. Officials said Medusa actors can exploit newly disclosed vulnerabilities within 24 hours, and in some cases were observed abusing flaws up to a week before public disclosure.
The advisory said Medusa gains access through initial access brokers, reportedly offering up to $1 million for exclusive access, and has exploited vulnerabilities including CVE-2024-1709, CVE-2023-48788, GoAnywhere MFT flaws, and CVE-2026-1731. Once inside, operators use living-off-the-land techniques, credential dumping, stolen or vulnerable drivers, and legitimate remote monitoring and management tools to disable security controls, move laterally, steal sensitive data, and encrypt networks. Authorities also described aggressive extortion tactics such as rapid-payment discounts and paid deadline extensions, while urging organizations to patch quickly, segment networks, enforce phishing-resistant MFA, maintain offline immutable backups, and monitor for unauthorized RMM activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On Tuesday, CISA, the FBI, and HHS issued an updated joint advisory on Medusa ransomware, warning that the group is actively infiltrating enterprise networks, stealing data, disabling security tools, and encrypting systems. The bulletin included indicators of compromise and mitigation guidance, and reflected forensic findings through April 2026.
The updated advisory said Medusa had compromised more than 500 organizations as of April 2026, up from about 300 victims previously reported in 2025.
The Record reported that Medusa shut down the University of Mississippi Medical Center in April, highlighting the group's impact on the healthcare sector.
The updated 2026 warning explicitly states it revised a March 2025 advisory about Medusa ransomware activity issued by CISA and the FBI.
In February 2023, Medusa attacked Minneapolis Public Schools and demanded a $1 million ransom. After the district refused to pay, the group leaked more than 100,000 sensitive records.
Around 2023, Medusa transitioned from a closed operation to an affiliate-based ransomware-as-a-service model, with core developers supplying payloads and affiliates participating for a share of extortion revenue.
U.S. authorities said Medusa was first observed in June 2021 and initially operated as a closed ransomware group before later changing its model.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceinfosecurity-magazine.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcecybersecuritynews.com
Open sourcecontent.govdelivery.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.