August 24, 2026
By esentry Team

Medusa Ransomware: 500+ Critical Infrastructure Victims and a Faster Route to Extortion

Threat Overview

500 victims. Six critical infrastructure sectors. A ransomware operation that can turn a newly disclosed vulnerability into an entry point in less than a day.

That is the picture emerging from an updated joint advisory released by the FBI, CISA and HHS on August 18, 2026. The agencies report that Medusa ransomware has now impacted more than 500 organizations, a sharp increase from the 300+ victims identified when the advisory was first released in March 2025. The victims span Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services, alongside organizations in education, legal, insurance and other industries.  

Medusa first emerged in 2021, but its business model has evolved. What began as a closed ransomware operation has developed into a Ransomware-as-a-Service (RaaS) operation, with affiliates and Initial Access Brokers helping turn compromise into a scalable business. Rather than doing everything themselves, Medusa's operators can effectively buy the pieces they need: access to a victim, tools to move through the network, and infrastructure to execute the final extortion.

And that is where Medusa becomes particularly interesting.

The operation is not simply "break in, encrypt files, demand Bitcoin." It is an ecosystem built around speed, purchased access, stolen credentials, legitimate administration tools and data theft.

Key Points

  • 500+ critical infrastructure organizations have reportedly been impacted by Medusa ransomware, up from more than 300 victims identified in the original 2025 advisory.  
  • Medusa operates under a Ransomware-as-a-Service (RaaS) model and relies on Initial Access Brokers (IABs) to obtain access to organizations.  
  • The group has demonstrated rapid exploitation of newly disclosed vulnerabilities, sometimes exploiting vulnerabilities within 24 hours of disclosure and, in some cases, before public disclosure.  
  • Medusa affiliates heavily abuse legitimate administrative and remote-management tools, making malicious activity harder to distinguish from normal IT operations.  
  • The operation follows a double-extortion model, stealing sensitive data before encrypting systems and threatening to publish the stolen information.  
  • Critical infrastructure sectors affected include Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services.  

The Dark Web Business Behind Medusa

The most interesting part of Medusa's operation may not be the ransomware itself but the market around it.

Medusa's affiliate model allows different actors to specialize in different stages of an intrusion. An Initial Access Broker can compromise an organization and sell the foothold. An affiliate can then take over, expand access, steal data and deploy the ransomware. The result is a division of labour that makes ransomware operations faster and easier to scale.

That means the attacker does not necessarily need to spend weeks trying to breach an organization from scratch, someone may already have the door open, and the ransomware operator simply needs to buy the key.

The FBI, CISA and HHS found that Medusa actors have exploited newly announced vulnerabilities within 24 hours of disclosure. In some cases, exploitation occurred before public disclosure, with the advisory noting instances where exploits were used up to a week early.  

The operation has been associated with vulnerabilities including:

  • CVE-2024-1709 — ConnectWise ScreenConnect
  • CVE-2023-48788 — Fortinet FortiOS/FortiProxy/FortiManager-related vulnerability
  • CVE-2025-10035 — Fortra GoAnywhere MFT
  • CVE-2026-1731 — BeyondTrust

Attack Methodology

Medusa affiliates have been observed using multiple paths to gain and maintain access:

  • Initial Access: Phishing campaigns used to steal credentials and exploitation of vulnerable internet-facing applications.
  • Vulnerability Exploitation: Exploitation of vulnerabilities in products including ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust.
  • Credential Access: Tools and techniques such as Mimikatz, Task Manager, and comsvcs.dll have been used to obtain credentials and dump LSASS memory.
  • Discovery: PowerShell, Command Prompt, Windows Management Instrumentation (WMI), Advanced IP Scanner, and SoftPerfect Network Scanner have been used for network and system discovery.
  • Lateral Movement: Remote Desktop Protocol (RDP), PsExec, and legitimate remote management tools have been used to move through compromised environments.
  • Persistence and Control: Attackers have abused legitimate remote access and management software already present within victim environments, including AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop.
  • Data Exfiltration: Stolen information has been packaged using Bandizip and transferred using Rclone and other available mechanisms.
  • Encryption: The ransomware can terminate backup, security, database, communications, and other services before deleting shadow copies and encrypting files.

Why It Matters

Medusa's activity highlights the growing risk posed by ransomware groups that combine rapid vulnerability exploitation, access brokers, legitimate administrative tools, credential theft, data exfiltration, and ransomware deployment within a single operation.

The ability to exploit newly disclosed vulnerabilities within hours significantly reduces the window available to organizations for patching vulnerable internet-facing systems. At the same time, the use of legitimate remote management tools and native administrative utilities can make malicious activity more difficult to distinguish from normal IT operations.

For organizations operating critical infrastructure, a successful Medusa intrusion could therefore progress from initial compromise to credential theft, lateral movement, data theft, and ransomware deployment before conventional detection and response processes are able to contain the attack.

Recommendations

Organizations should focus on detecting the activity before encryption becomes the story.

Priority areas include:

  • Rapidly patch internet-facing applications, especially vulnerabilities known to be actively exploited.
  • Monitor for newly created privileged accounts and unexpected privilege escalation.
  • Investigate unusual use of remote-management software, particularly where the software was not previously approved.
  • Monitor RDP, PsExec, WMI and PowerShell activity for unusual lateral-movement patterns.
  • Protect credentials and monitor LSASS and other credential-dumping activity.
  • Segment critical systems to limit lateral movement following an initial compromise.
  • Monitor unusual outbound data transfers and the use of tools such as Rclone for potential exfiltration.
  • Maintain offline, immutable and regularly tested backups.
  • Treat newly disclosed vulnerabilities as an intelligence problem, not simply a patch-management problem: know which vulnerabilities attackers are likely to weaponize before they reach your environment.

Intelligence Takeaway

With more than 500 critical infrastructure victims now attributed to the operation, Medusa demonstrates how the ransomware underground continues to industrialize its attack chain, turning compromise into a service, access into a commodity, and stolen data into leverage.

For defenders, the lesson is simple:

Do not wait for the ransom note. By then, the interesting part of the attack had already happened.