CISA, FBI: Medusa Ransomware Has 500+ Victims
CISA and the FBI updated their Medusa ransomware advisory, confirming the group has hit more than 500 organizations in critical infrastructure since 2021.

Medusa ransomware actors have compromised more than 500 organizations as of April 2026, according to an updated joint advisory released Monday by the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI. The group’s previous confirmed victim count — 300, as of CISA’s original March 2025 advisory — has grown by more than 65 percent in roughly 14 months. Critical infrastructure sectors are disproportionately represented in the tally: healthcare, education, legal services, insurance, and technology.
The count increase matters less as a headline number and more as a signal about operational tempo. Groups that face meaningful law enforcement disruption typically fragment, rebrand, or go quiet. Medusa has done none of those things. It is, by the numbers, still running.
What Medusa Actually Does
Medusa operates as a ransomware-as-a-service (RaaS) platform. Affiliates handle initial access and lateral movement; the core group supplies the encryptor and the negotiation infrastructure. Initial access most commonly arrives through phishing campaigns and exploitation of unpatched internet-facing services. Once inside, affiliates move laterally, stage data for exfiltration, and then deploy encryption — double extortion with a dedicated leak site, “Medusa Blog,” used to pressure victims who attempt to recover without paying.
The technical profile is not novel. What the updated advisory documents is persistence: Medusa has maintained consistent operational tempo through a period when several larger RaaS operators (ALPHV/BlackCat, LockBit) were either disrupted or underwent significant internal fracturing.
What the Advisory Says to Do
CISA and the FBI outline a standard hardening posture for organizations that want to reduce exposure:
- Enable multi-factor authentication on all remote access pathways, including VPN and web-based email
- Patch internet-facing systems promptly — Medusa affiliates regularly probe for known vulnerabilities in exposed services
- Restrict or disable Remote Desktop Protocol (RDP) where it does not need to be externally accessible; the advisory specifically calls out RDP as a consistent initial access vector across confirmed Medusa victims
- Segment networks to limit lateral movement in the event of a successful intrusion
- Maintain tested, offline backups — emphasis on tested; a backup that has never been exercised is not a recovery plan
The RDP callout in the advisory is the concrete starting point. If your environment has RDP instances with external exposure — whether from a misconfigured firewall rule, a temporarily opened port that was never closed, or remote administration tooling left in a default configuration — that surface is the first thing the advisory implies Medusa would try to leverage.
Prior Coverage
Today’s Medusa advisory update arrives alongside a separate CISA KEV addition involving a Windows Task Host vulnerability now confirmed exploited by ransomware gangs — see CISA: Ransomware Gangs Now Exploit Windows Task Host Flaw. The two advisories are independent but reinforce the same posture guidance: patch exposed systems, verify your MFA coverage, and confirm that your backup restoration process has been tested recently.
Source: The Record — joint CISA/FBI advisory, updated August 18, 2026.
Found this useful? Share it.


