Medusa ransomware’s victim count has passed 500, a fresh joint advisory from the FBI, CISA, and the Department of Health and Human Services says. The revised guidance, published August 18, extends a March 2025 alert with FBI casework through April 2026.
Healthcare, defense, manufacturing, government services, IT, and financial services top the victim list, with education, insurance, and law firms also hit. The count climbed from 300-plus to 500-plus in just over a year.
Medusa began as a closed operation and moved to an affiliate model by early 2023. Affiliates earn trust by experience and profitability, and the group buys footholds from initial access brokers for $100 to $1 million. Most brokers juggle several ransomware variants at once.
ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust flaws have served as recent entry points. The group turns newly disclosed exploits around within 24 hours, sometimes using them a week before public disclosure, yet shows no sign of building its own zero-days.
Once inside, Medusa favors tools already present on the network. PowerShell, Mimikatz, AnyDesk, and SimpleHelp handle credential theft and remote access, while a process called gaze.exe shuts down backup and security services before locking files with a .medusa extension.
The extortion playbook is double-edged. A ransom note gives victims 48 hours before direct contact, stolen data lands on a leak site with a countdown timer, and $10,000 in crypto buys an extra day.
Defenders should patch internet-facing systems, segment networks, and block untrusted traffic to remote access services. The agencies continue to advise against paying ransoms.
