What happened
Medusa ransomware was first identified in June 2021. The operation developed into a ransomware-as-a-service model in which developers and affiliates use data theft, encryption and public-release threats to pressure victims. Federal guidance describes a double-extortion operating model and the use of initial-access brokers alongside direct intrusion activity.
The March 12, 2025 joint advisory reported more than 300 victims as of February 2025. On August 18, 2026, the FBI, CISA and HHS updated AA25-071A with investigation material current to April 2026. The updated advisory says Medusa developers and affiliates had impacted more than 500 victims across multiple critical-infrastructure sectors as of April 2026.
The affected sectors named include healthcare, defence industrial base, critical manufacturing, government services, information technology and financial services, with additional victims in education, legal, insurance and technology organisations. The advisory says affiliate recruitment offers ranged from $100 to $1 million. That range describes recruitment incentives reported by the agencies; it is not a confirmed ransom payment, loss figure or price for any specific victim.
Attribution posture: The FBI, CISA and HHS attribute the ransomware activity to Medusa developers and affiliates; the cited update does not identify individual operators or a state sponsor. Neither the advisory nor the cited reporting names the more than 500 affected organisations. No revision-specific hash, IP address or domain was reproduced in the cited August 19 reporting, so this briefing does not assert one. The new victim count establishes cumulative impact, not that more than 500 organisations were attacked during the current publication window. The cited source did not publish the specific operational detail described as Named affected organisations. The cited source did not publish the specific indicators described as Revision-specific network indicators reproduced by current reporting.
Why this matters now
The revised federal count shows that Medusa remains an expanding operational threat rather than a dormant ransomware brand. Healthcare, financial services, manufacturing, government and technology organisations must assume affiliates continue to combine opportunistic edge exploitation, purchased access and double extortion against environments where downtime creates negotiating pressure.
The victim total is cumulative, not a forecast of imminent attacks against any named organisation. Its leadership value is the evidence that a familiar ransomware operation has continued scaling despite years of public guidance, indicating persistent gaps in Internet-facing asset ownership, segmentation, privileged access and recovery execution.
The addition of HHS to the updated advisory reinforces the healthcare consequence, where encryption and data theft can affect clinical operations, patient privacy and mandatory reporting simultaneously. Recovery exercises must therefore test service restoration, identity isolation, evidence preservation and external communications under the same scenario.
The decision for security leaders
Use the federal count as a challenge to operating assumptions, not as a probability model. Require proof that every Internet-facing service is owned, supported, monitored and covered by accelerated remediation authority, because unmanaged edge exposure remains a repeatable entry path for ransomware affiliates.
Measure the time to isolate identity, endpoints, virtualisation and backup administration without destroying forensic evidence or blocking recovery. A paper incident plan does not establish that teams can contain an affiliate before encryption and data theft become simultaneous executive problems.
Test recovery at the service level. Boards need evidence that an essential clinical, manufacturing, financial or public service can be restored from protected data while identity and production networks remain untrusted, including the communications and regulatory decisions required during double extortion.
Evidence of closure
- An exposure register shows no unsupported or unowned Internet-facing service.
- A witnessed exercise records the time to isolate identity, endpoints, virtualisation and backup planes.
- An offline restore test meets the approved recovery objective for one essential service.
- Incident-response retainers and government reporting contacts are current and tested.
The Security.io assessment
The updated count is meaningful because it records sustained impact across critical sectors after the original advisory. It does not prove a sudden August surge, and the briefing should not convert a cumulative federal statistic into a claim about the current number of active intrusions.
The operation’s affiliate model distributes intrusion execution across actors with varying tools and access paths. That reduces the value of treating Medusa as a single malware-signature problem and increases the importance of exposure management, behavioural detection, privileged-access containment and rehearsed recovery.
Current reporting does not provide a revision-specific hunt set or named victims. Organisations should retain the federal advisory as the authoritative TTP source, but closure should rest on their own edge inventory, identity evidence, segmentation validation and recovery results rather than an absence of matches to a short indicator list.
Questions for the morning meeting
- Can essential services be isolated without disabling the organisation’s recovery infrastructure?
- Which Internet-facing systems lack clear ownership or accelerated patch authority?
- Has the organisation tested simultaneous recovery demand across multiple business services?
- Do incident plans account for data theft and public extortion as well as encryption?