Published · 5d agoSecurity3 min read
Medusa's patch window is negative: 500 victims, and exploits used before disclosure
The updated CISA-FBI advisory puts Medusa at more than 500 victims as of April 2026, up from 300, with exploits weaponized within 24 hours and sometimes a week before disclosure.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- An updated U.S. government advisory on the Medusa ransomware-as-a-service group was published Tuesday by CISA, the FBI and the Health and Human Services Department, expanding a March 2025 advisory and drawing on ongoing FBI investigations.
- CISA and the FBI updated an advisory initially released in March 2025, writing that as of April 2026 Medusa actors have hit more than 500 victims.
- CISA previously said 300 victims, many in critical infrastructure sectors, had been attacked as of 2025.
- The advisory states: "Medusa actors leverage newly announced exploits within 24 hours and have been observed to use exploits up to a week before public vulnerability disclosure."
- The advisory says there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, preferring instead to obtain advanced access to exploits from unknown sources or to quickly use newly announced exploits before potential victims can mitigate through patching.
Compiled by The WatchSomething wrong?How this is made
Why it matters
CISA, the FBI and the Department of Health and Human Services updated their March 2025 advisory on Medusa ransomware on Tuesday, and the victim tally moved from more than 300 to more than 500 as of April 2026 [1][2][3]. The number is not the important part. The important part is a single sentence in the updated text: Medusa actors use newly announced exploits within 24 hours, and have been observed using exploits up to a week before the vulnerability was publicly disclosed [4]. That growth works out to roughly 200 additional victims across about 13 months, close to a two-thirds increase on the earlier count [1][2]. Most healthcare patch programmes are built on a clock that starts at disclosure. A critical-severity SLA of seven days, or the more common 30, is measured from the moment a vendor publishes. If a group is exploiting flaws before publication, that clock is measuring the wrong interval, and a team that hits its SLA every month can still be behind. The agencies are explicit that this is not a research capability: they say there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, and that they prefer to obtain advance access to exploits from unknown sources or to move on newly announced ones before victims can patch [5]. Bought lead time is cheaper to sustain than invented lead time, and it is available to anyone with the same budget. Medusa pays initial access brokers between $100 and $1 million, with the top of that range going to brokers who work exclusively for the group, and the advisory notes most brokers serve multiple ransomware variants at once [6][7]. The targeting logic follows from the tooling. The advisory says Medusa operates opportunistically against victims with unpatched software rather than picking specific organisations or sectors, while noting that the Healthcare and Public Health sector has been a frequent victim [8]. Named exploited products include Fortra GoAnywhere and BeyondTrust flaws [9]. BeyondTrust also appears on the FBI's list of legitimate remote access software Medusa actors have used once inside, alongside AnyDesk, Atera, ConnectWise, eHorus, N-able, SimpleHelp and Splashtop [10]. Adrian Culley of SafeBreach said actors tied to Medusa are moving from initial access to data exfiltration in hours rather than days [11]. The consequence, in April, was the University of Mississippi Medical Center: the state's only children's hospital, only Level I trauma center, only Level IV neonatal intensive care unit and home to its only organ transplant program, shut down [12]. One caveat on the 500 figure. Medusa has not posted a new victim to its leak site since April, and several researchers attribute that to the law enforcement attention the medical center attack attracted [13]. The count may be the ceiling of a paused operation rather than a live rate. The tradecraft does not pause with it. Microsoft documented a group it calls Storm-1175 running fast operations with Medusa ransomware [14], and Symantec and Carbon Black described North Korean hackers using Medusa against the health care sector [15]. Medusa moved to an affiliate model in 2023, with ransom negotiation centrally handled by developers for less experienced affiliates [16], which is a structure designed to survive the loss of any given operator. The rest of the economics is unchanged and worth reading before an incident, not during one. Victims are commonly offered $10,000 to buy one extra day before stolen data is published [17]. In one case seen by FBI investigators, a victim who had already paid was contacted by a separate Medusa actor claiming the negotiator stole the money and demanding half again for the "true decryptor", which the agencies read as either triple extortion or internal dysfunction [18]. Watch whether the leak site stays dark or a successor brand appears with the same broker relationships.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
An updated U.S. government advisory on the Medusa ransomware-as-a-service group was published Tuesday by CISA, the FBI and the Health and Human Services Department, expanding a March 2025 advisory and drawing on ongoing FBI investigations.
- [2]
CISA and the FBI updated an advisory initially released in March 2025, writing that as of April 2026 Medusa actors have hit more than 500 victims.
ReportedView cited source - [3]
CISA previously said 300 victims, many in critical infrastructure sectors, had been attacked as of 2025.
ReportedView cited source - [4]
The advisory states: "Medusa actors leverage newly announced exploits within 24 hours and have been observed to use exploits up to a week before public vulnerability disclosure."
ReportedView cited source - [5]
The advisory says there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, preferring instead to obtain advanced access to exploits from unknown sources or to quickly use newly announced exploits before potential victims can mitigate through patching.
ReportedView cited source - [6]
The advisory says Medusa relies on access brokers, compensating them anywhere from $100 to $1 million, with higher prices going to those who work exclusively with Medusa.
ReportedView cited source
Sources & coverage · 7 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cyberscoop.comTim Starks5d agoMedusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
- therecord.media5d agoMore than 200 victims of Medusa ransomware identified over the last year, CISA says
- bleepingcomputer.comSergiu Gatlan4d agoCISA: Medusa ransomware hit over 500 critical infrastructure orgs



