What happened
On August 18-19, CISA, the FBI, and the Department of Health and Human Services jointly updated their advisory on Medusa, a ransomware-as-a-service (RaaS) operation that has now compromised more than 500 critical infrastructure organizations in the United States since it first appeared in mid-2021. That figure is up sharply from the roughly 300 victims the same agencies reported in March 2025 — meaning Medusa has hit more organizations in the last 17 months than in its first four years of operation combined.
The update is not a one-off alert about a single breach. It is a formal reassessment of a group the federal government now treats as a persistent, escalating threat to essential services, and it comes with specific technical detail on how the group operates that CISOs should be feeding into their own risk assessments now.
Why this advisory matters more than most
Ransomware advisories are routine; this one stands out for three reasons.
Scale and acceleration. A 65%-plus increase in confirmed victims within a year and a half signals an operation that is scaling, not slowing, despite two years of law enforcement attention, sanctions activity against affiliated actors, and a prior advisory. For boards, this undercuts any assumption that current sector-wide defenses are containing the threat.
Sector concentration in healthcare. The advisory singles out Healthcare and Public Health as one of the most frequently hit sectors, alongside Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. Healthcare organizations face a distinct risk stack here: patient safety exposure, HIPAA breach notification obligations, and — for hospital systems — potential care disruption that regulators and plaintiffs’ attorneys now treat as foreseeable, not exceptional.
A maturing, RaaS-driven business model. Medusa operates as an affiliate program. Its operators purchase network access from initial access brokers for sums ranging from $100 to as much as $1 million for exclusive footholds, and affiliates have been observed weaponizing newly disclosed vulnerabilities — including flaws in ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust — within 24 hours of public disclosure. This is a direct challenge to standard patch-cycle assumptions: a monthly or even weekly patch cadence is not fast enough against an affiliate ecosystem operating on a one-day timeline.
How the group operates
Two operational details are worth escalating to your security and IT operations leadership directly, because they affect detection strategy rather than just patching priority.
First, Medusa affiliates lean heavily on legitimate, already-installed tools — PowerShell, Mimikatz, AnyDesk, and SimpleHelp — rather than custom malware. This “living off the land” approach is deliberately built to blend into normal administrative activity and evade signature-based detection, which means endpoint detection and response (EDR) tuning and behavioral analytics matter more here than traditional antivirus coverage.
Second, the group runs a structured double-extortion playbook: victims are given roughly 48 hours to respond before Medusa initiates direct contact and posts stolen data to a leak site with a public countdown timer. Victims can pay approximately $10,000 in cryptocurrency to buy a single additional day of negotiation time before publication. This is a pressure mechanism explicitly designed to force a decision before legal, communications, and executive teams have had time to convene — which is precisely why an incident response plan with pre-authorized decision authority matters more than a plan that assumes days of deliberation.
Governance implications
For boards and executive teams, three questions should come out of this advisory:
-
Are we in one of the named sectors, or do we depend on suppliers who are? Healthcare, defense, manufacturing, government services, IT, and financial services organizations should treat this as a direct, current threat rather than background noise. Organizations outside these sectors should still ask whether critical vendors or managed service providers sit inside them.
-
Can we patch newly disclosed vulnerabilities in named products faster than 24 hours, and do we know if ScreenConnect, Fortinet EMS, Fortra GoAnywhere, or BeyondTrust are in our environment? If any of these tools are deployed, confirm current patch status and access logging as a priority this week, not at the next scheduled patch cycle review.
-
Does our incident response plan assume a 48-hour extortion clock, and who is authorized to make a pay/no-pay recommendation within that window? If the answer requires convening a committee that cannot meet inside two days, the plan needs revision. This is also a natural discussion point for the next board or risk committee meeting: ask management to walk through the decision chain against Medusa’s actual timeline, not a hypothetical one.
The bottom line
Federal agencies do not typically revise victim counts upward by this margin without cause. The joint CISA-FBI-HHS advisory is a signal that this group’s affiliate model is currently outpacing sector-wide defenses, particularly in healthcare. For CISOs, the immediate value of the update is tactical — the named vulnerable products and the living-off-the-land tooling give concrete detection and patching priorities. For boards, the value is in the governance question it raises: whether the organization’s incident response cadence is built for a 48-hour extortion window or a slower one that no longer reflects how these attacks actually unfold.