CISA and FBI say Medusa ransomware hit more than 500 victims and is heavily targeting healthcare

CISA and the FBI say the Medusa ransomware group has hit more than 500 victims as of April 2026, up from 300 previously disclosed, with many victims in critical infrastructure and a strong focus on healthcare. The agencies updated a joint advisory to say Medusa affiliates often exploit newly announced flaws within 24 hours and in some cases have used exploits up to a week before public disclosure, while also using tools such as AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop during intrusions.
Why it matters: Organizations, especially healthcare providers and other critical infrastructure operators, should treat this as an urgent warning to patch quickly, review remote-access tools, and hunt for credential theft and lateral movement. For the public, it signals ongoing risk of service disruptions at hospitals and local governments if defenses lag behind newly disclosed vulnerabilities.

Sources

CISA: Medusa ransomware hit over 500 critical infrastructure orgs
Sergiu Gatlan 2026.08.19 98% relevant
This article is a direct report on the same joint CISA-FBI-HHS advisory, adding the updated scope that Medusa has impacted more than 500 critical infrastructure victims since June 2021 and reiterating the affected sectors and mitigation guidance.
More than 200 victims of Medusa ransomware identified over the last year, CISA says
2026.08.18 100% relevant
This article establishes a distinct tracked story around the updated CISA/FBI Medusa advisory, specifically the jump to 500+ victims, healthcare targeting, and the group's rapid exploitation behavior.
← Back to all stories