Are you safe from Medusa?
- Ben Card

- 11 minutes ago
- 5 min read
Medusa Ransomware Victim Count Now at 500 US Firms: The New Federal Advisory and What It Means for You

A New Milestone in a Long-Running Ransomware Campaign
On August 18, 2026, the FBI, CISA, and the US Department of Health and Human Services released an updated joint advisory confirming that the Medusa ransomware operation has now compromised more than 500 organizations across US critical infrastructure since the group first surfaced in 2021. The update, published as part of the ongoing StopRansomware series, replaces a March 2025 advisory that had put the total closer to 300, marking one of the sharpest documented escalations in a single ransomware campaign's known victim count within a twelve-month period. Reporting on the updated numbers makes clear just how quickly a once mid-tier ransomware-as-a-service operation has climbed toward the top of the federal government's list of active threats to US organizations.
Federal agencies attribute more than 200 of those newly confirmed victims to the past twelve months alone, according to detailed reporting on the advisory, with the running tally crossing the 500 mark following an attack on a Mississippi hospital system earlier this year. The organizations affected span healthcare and public health, the defense industrial base, critical manufacturing, government services and facilities, information technology, and financial services, alongside a long tail of victims in education, legal services, insurance, and general manufacturing. That breadth is the real headline for most readers here: Medusa is not a healthcare-only problem or a small-business problem, it is a cross-sector campaign that has already reached into nearly every major category of the US economy.
Inside the Medusa Playbook
Medusa operates as a ransomware-as-a-service enterprise, meaning the core group develops and maintains the malware and negotiation infrastructure while independent affiliates carry out the actual intrusions in exchange for a cut of the proceeds. Federal investigators say affiliates are recruited openly on cybercriminal forums. Payouts reportedly range from around 100 dollars for smaller support tasks up to 1 million dollars for affiliates who deliver high-value victims. This structure has allowed the operation to scale far beyond what a single tightly held crew could manage. Much of that scale traces back to how affiliates get in the door in the first place: often through internet-facing systems carrying vulnerabilities that already appear on CISA's known exploited vulnerabilities catalog. The vulnerabilities are used long before most victim organizations get around to patching them.

Once inside, Medusa affiliates move fast. Investigators have documented cases where attackers weaponized a newly disclosed vulnerability within 24 hours of its publication. In at least a few instances they appear to have exploited flaws before they were ever publicly disclosed. Rather than relying solely on custom malware that might trip up endpoint defenses, affiliates frequently pivot to legitimate remote monitoring and management tools already trusted on corporate networks, including products like AnyDesk, Atera, ConnectWise, and Splashtop, to move through an environment while looking like ordinary IT traffic. The result, according to one incident responder quoted in coverage of the advisory, is an operation that can go from initial access to full data exfiltration in a matter of hours rather than the days or weeks defenders have historically had to detect and respond.
Compliance Exposure Extends Well Beyond Healthcare
Because healthcare has absorbed a disproportionate share of Medusa's attention, it is worth pausing on what a successful attack actually triggers for a covered entity or business associate. Under the HIPAA Security Rule, organizations that handle electronic protected health information are already required to maintain administrative, physical, and technical safeguards. A ransomware event that encrypts or exposes that data generally starts the clock on breach notification obligations to affected individuals, the HHS Office for Civil Rights, and, in larger incidents, the media. HHS has also proposed updates that would tighten several of those existing Security Rule requirements, a signal that regulators are treating ransomware as a driver of policy change rather than background noise.
Financial services and other institutions covered by the Gramm-Leach-Bliley Act face a parallel set of obligations under the FTC Safeguards Rule. It requires a documented information security program and, for breaches affecting 500 or more consumers, direct notification to the FTC itself. Layered on top of federal sector rules is a patchwork of state data breach notification laws, several of which, including California's, require businesses to notify the state attorney general once a breach crosses a similar 500-resident threshold. Any organization sitting at the intersection of several of these regimes, which describes a large share of mid-sized US businesses, can find a single Medusa intrusion triggering notification duties in multiple directions at once.
What US Organizations Should Do Now

The advisory's core recommendations are not exotic, but they are specific enough to act on this week. CISA's StopRansomware hub lays out prioritized vulnerability scanning of internet-facing systems, prompt patching, and network segmentation as the baseline defenses that would have blunted a meaningful share of Medusa intrusions to date. Organizations looking for a broader structure to hang those controls on can map their program to the NIST Cybersecurity Framework, which now includes a dedicated ransomware profile built for exactly this kind of threat.
Because affiliates lean so heavily on legitimate remote access software, security teams should also inventory which remote monitoring and management tools are actually authorized on their networks. Next, alert on anything outside that list, treat multifactor authentication on remote access and privileged accounts as non-negotiable, and keep offline, tested backups that a ransomware actor cannot reach through the same credentials used to encrypt production data. Organizations that experience an intrusion, or even suspect one, should report it to the FBI's Internet Crime Complaint Center quickly. This quick reporting is to get access to federal incident response resources and because the resulting data is what allows future advisories like this one to reflect the real scope of the threat.
Get Ahead of the Next Advisory

Advisories like this one are, by design, a look in the rearview mirror. The 500 organizations named in this update were all breached before the report was ever published, and the next update will almost certainly describe a higher number, because Medusa's affiliate model rewards continued growth rather than caution. The more useful question for any organization reading this is not where Medusa has already struck, but where it will strike again. The specific gaps this campaign keeps exploiting, unpatched internet-facing systems, unmonitored remote access tools, and thin backup and recovery practices, exist somewhere in its own environment right now.
If your organization has not recently tested how it would hold up against a Medusa-style intrusion, from initial access through exfiltration and the compliance notifications that would follow, that gap is worth closing before it gets closed for you. Webcheck Security works with US businesses and other organizations to run the vulnerability assessments, penetration tests, and compliance reviews that turn advisories like this one into a concrete action plan rather than another headline to read past.
Reach out to Webcheck Security to talk through where your organization stands and what a realistic, prioritized remediation plan would look like for your environment.




Comments