Security7 distinct publishers3 min readPublished Updated
The updated CISA-FBI advisory puts Medusa at more than 500 victims as of April 2026, up from 300, with exploits weaponized within 24 hours and sometimes a week before disclosure.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
CISA, the FBI and the Department of Health and Human Services updated their March 2025 advisory on Medusa ransomware on Tuesday, and the victim tally moved from more than 300 to more than 500 as of April 2026 [1][2][3]. The number is not the important part. The important part is a single sentence in the updated text: Medusa actors use newly announced exploits within 24 hours, and have been observed using exploits up to a week before the vulnerability was publicly disclosed [4]. That growth works out to roughly 200 additional victims across about 13 months, close to a two-thirds increase on the earlier count [1][2]. Most healthcare patch programmes are built on a clock that starts at disclosure. A critical-severity SLA of seven days, or the more common 30, is measured from the moment a vendor publishes. If a group is exploiting flaws before publication, that clock is measuring the wrong interval, and a team that hits its SLA every month can still be behind. The agencies are explicit that this is not a research capability: they say there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, and that they prefer to obtain advance access to exploits from unknown sources or to move on newly announced ones before victims can patch [5]. Bought lead time is cheaper to sustain than invented lead time, and it is available to anyone with the same budget. Medusa pays initial access brokers between $100 and $1 million, with the top of that range going to brokers who work exclusively for the group, and the advisory notes most brokers serve multiple ransomware variants at once [6][7]. The targeting logic follows from the tooling. The advisory says Medusa operates opportunistically against victims with unpatched software rather than picking specific organisations or sectors, while noting that the Healthcare and Public Health sector has been a frequent victim [8]. Named exploited products include Fortra GoAnywhere and BeyondTrust flaws [9]. BeyondTrust also appears on the FBI's list of legitimate remote access software Medusa actors have used once inside, alongside AnyDesk, Atera, ConnectWise, eHorus, N-able, SimpleHelp and Splashtop [10]. Adrian Culley of SafeBreach said actors tied to Medusa are moving from initial access to data exfiltration in hours rather than days [11]. The consequence, in April, was the University of Mississippi Medical Center: the state's only children's hospital, only Level I trauma center, only Level IV neonatal intensive care unit and home to its only organ transplant program, shut down [12]. One caveat on the 500 figure. Medusa has not posted a new victim to its leak site since April, and several researchers attribute that to the law enforcement attention the medical center attack attracted [13]. The count may be the ceiling of a paused operation rather than a live rate. The tradecraft does not pause with it. Microsoft documented a group it calls Storm-1175 running fast operations with Medusa ransomware [14], and Symantec and Carbon Black described North Korean hackers using Medusa against the health care sector [15]. Medusa moved to an affiliate model in 2023, with ransom negotiation centrally handled by developers for less experienced affiliates [16], which is a structure designed to survive the loss of any given operator. The rest of the economics is unchanged and worth reading before an incident, not during one. Victims are commonly offered $10,000 to buy one extra day before stolen data is published [17]. In one case seen by FBI investigators, a victim who had already paid was contacted by a separate Medusa actor claiming the negotiator stole the money and demanding half again for the "true decryptor", which the agencies read as either triple extortion or internal dysfunction [18]. Watch whether the leak site stays dark or a successor brand appears with the same broker relationships.
Ranked by verification strength, evidence, and original report placement.
An updated U.S. government advisory on the Medusa ransomware-as-a-service group was published Tuesday by CISA, the FBI and the Health and Human Services Department, expanding a March 2025 advisory and drawing on ongoing FBI investigations.
CISA and the FBI updated an advisory initially released in March 2025, writing that as of April 2026 Medusa actors have hit more than 500 victims.
CISA previously said 300 victims, many in critical infrastructure sectors, had been attacked as of 2025.
The advisory states: "Medusa actors leverage newly announced exploits within 24 hours and have been observed to use exploits up to a week before public vulnerability disclosure."
The advisory says there is no indication Medusa actors develop their own zero-day or N-day vulnerabilities, preferring instead to obtain advanced access to exploits from unknown sources or to quickly use newly announced exploits before potential victims can mitigate through patching.
The advisory says Medusa relies on access brokers, compensating them anywhere from $100 to $1 million, with higher prices going to those who work exclusively with Medusa.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary government advisory, corroborated by two independent outlets
The core factual base is a joint CISA/FBI/HHS advisory drawing on ongoing FBI investigations, reported consistently by two publishers with no contradictions on victim counts, exploitation windows, tooling or extortion mechanics. It is bolstered by named third-party research from Microsoft, Symantec and Carbon Black. Evidence stops short of top marks because the striking pre-disclosure exploitation claim is an unelaborated government assertion with no published indicators, case detail or timeline in either source.
Documented criminal scale: 500-plus victims, but a dormant leak site
Real-world footprint is directly quantified: more than 500 victims as of April 2026, roughly 200 added in about a year, a mature affiliate model with a broker supply chain, named tooling, and at least one severe healthcare outage. The reading is held below the top band because the same reporting notes no new leak-site victims since April, so current operational tempo is unclear.
Mildly overstated urgency: the sharpest framing rests on one advisory sentence
The cluster's framing of a negative patch window rests entirely on a single unelaborated advisory sentence about use of exploits up to a week before disclosure, while the advisory itself says Medusa develops no zero-days of its own and operates opportunistically against unpatched software. One outlet's own reporting notes the group has posted no new victims since April, and only one outlet's expert supplies the hours-not-days speed figure. The verified scale claims are solid, so the gap is modest rather than large.
Agency advocacy plus one vendor voice, disclosed
The primary document comes from agencies with a mission interest in driving patch urgency and incident reporting, and the only outside expert quoted works for a security vendor whose commentary reinforces demand for breach simulation and detection tooling. Both incentives are visible on the page and attributed, and the specific technical content (product names, tooling lists, broker pricing) is verifiable rather than promotional, which limits distortion.
High confidence on facts, lower on current tempo and pre-disclosure claim
Two independent outlets agree on all load-bearing facts sourced to a primary government document, so the factual spine is dependable. Confidence is capped by unresolved questions the sources leave open: whether Medusa is currently active, what the pre-disclosure exploitation assertion is based on, and whether the leak-site pause reflects law enforcement pressure, since that link is expert inference only.
security
CISA orders Ray patched as RondoDox folds cluster software into a 174-exploit arsenal1 distinct publisher
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher
product
DOJ downgraded its hacking victims to targets two days after the headlines ran1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
bleepingcomputer.com
1 article · August 19, 2026
cisa.gov
1 article · August 20, 2026
cyberscoop.com
2 articles · August 20, 2026
helpnetsecurity.com
1 article · August 19, 2026
infosecurity-magazine.com
1 article · August 19, 2026
scworld.com
1 article · August 19, 2026
therecord.media
1 article · August 18, 2026