Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—reported victims impacted by Medusa have increased across the latest federal snapshots. But those snapshots are cumulative counts at two dates, not a complete annual series, so they do not establish a year-over-year attack rate or explain what caused the increase.

What do the latest Medusa victim counts show?

Snapshot date Reported impacted victims Source
February 2025 More than 300 FBI, CISA, and MS-ISAC joint advisory
April 2026 More than 500 CISA, FBI, and HHS joint advisory update

The later count is higher, which supports an increase in reported impacted victims between those snapshots. It does not show how many new victims were added in each month or year, provide a denominator for calculating a rate, or establish that the increase will continue. The updated advisory, published August 18, 2026, reflects FBI investigations through April 2026.

What is Medusa ransomware, and how does its operation work?

Medusa is a ransomware-as-a-service (RaaS) operation first identified in June 2021, according to the agencies. It is separate from MedusaLocker ransomware and the Medusa mobile malware variant. In a RaaS model, developers provide ransomware capabilities and affiliates carry out attacks; the operation began as a closed group and shifted to an affiliate model by at least early 2023. Developers may retain control of important tasks, including negotiations, especially for newer or less experienced affiliates. The August 2026 advisory update and joint technical advisory describe the operation.

Why is it called double extortion?

Medusa combines file or system encryption with data theft and a threat to publish the stolen information if the victim does not pay. That puts pressure on an organization even if it can restore encrypted systems from backups: disclosure of sensitive data can create separate operational, legal, and reputational consequences. The authoring agencies describe the model as “encrypting systems and threatening to publish exfiltrated data if victims do not pay.” CISA, FBI, and HHS

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Bitdefender Total Security - 10 Devices | 2 year Subscription | PC/MAC |Activation Code by email
  • SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows, Mac OS, iOS, and Android. Organize and keep your digital life safe from hackers.
  • ADVANCED THREAT DEFENSE: Your software is always up-to-date to defend against the latest attacks, and includes: complete real-time data protection, multi-layer malware, ransomware, cryptomining, phishing, fraud, and spam protection, and more.
  • SUPERIOR PRIVACY PROTECTION: including a dedicated safe online banking browser, microphone monitor, webcam protection, anti-tracker, file shredder, parental controls, privacy firewall, anti-theft protection, social network protection, and more.
  • TOP-TIER PERFORMANCE: Bitdefender technology provides near-zero impact on your computer’s hardware, including: Autopilot security advisor, auto-adaptive performance technology, game/movie/work modes, OneClick Optimizer, battery mode, and more

How do Medusa actors get access?

The joint advisory describes several routes rather than one defining entry method. Actors may use access obtained from initial-access brokers, phishing, or exploitation of unpatched vulnerabilities—particularly on internet-facing systems. Agencies say the actors target vulnerable systems opportunistically rather than focusing on a specific organization or sector, and may quickly exploit newly announced vulnerabilities. The joint advisory also describes their use of legitimate administrative tools and “living off the land” techniques after access. These approaches can make malicious activity resemble routine system administration, so organizations should not rely on malware signatures alone.

Who is at risk?

The agencies report victims across critical-infrastructure sectors, including Healthcare and Public Health, the Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. They also list organizations in medical, education, legal, insurance, technology, and manufacturing fields. Healthcare and Public Health is identified as a frequent victim sector, but the advisory’s description of opportunistic targeting is not limited to healthcare. The sector information and the advisory’s targeting details are from the federal agencies.

Rank #2
Cryptnox FIDO2 Security Key with MIFARE DESFire NFC Smart Card for 2FA MFA
  • HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
  • BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
  • CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
  • DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
  • SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can an organization reduce its risk?

The agencies’ guidance focuses on reducing exposed entry points, limiting what an intruder can reach, spotting suspicious activity, and making recovery viable. Prioritize controls according to the systems and services exposed in your own environment; no single control replaces the others. The joint advisory’s mitigation section provides the detailed recommendations.

Close exposed paths into the network

  • Patch software and firmware promptly, prioritizing known-exploited vulnerabilities on internet-facing systems.
  • Require phishing-resistant multifactor authentication where possible, particularly for webmail, VPNs, and accounts that can access critical systems.
  • Secure remote access through VPNs or jump hosts, and filter untrusted origins from internal remote services.

Limit movement and detect misuse

  • Segment networks so that a compromised account or device cannot freely reach critical systems.
  • Apply least privilege, review accounts for unfamiliar or unrecognized users, and monitor network traffic for signs of lateral movement.
  • Validate security controls against the behaviors described in the advisory. Because actors use legitimate tools, monitoring should look for suspicious use and context, not only unfamiliar executables.

Build recoverable backups

Maintain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, secure location. Keep offline copies, encrypt backup data, use immutable backups where feasible, and cover the organization’s full data infrastructure. Practice both backup and restoration regularly so the organization can verify that recovery works. A hard drive, storage device, or cloud storage can be one component of a backup arrangement; a single external drive, especially one left connected to the network, is not by itself a complete offline recovery strategy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Cryptnox FIDO2 Security Key White PVC - Customizable NFC Card for 2FA MFA
  • CUSTOMIZABLE BLANK FACE: White PVC card ready for in-house printing so you can add your own logo, employee ID or branding to a working FIDO2 security key
  • HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP Level 1 for phishing-resistant login on compatible FIDO2 and WebAuthn services
  • PASSKEY READY: Serves as a WebAuthn passkey and enables passwordless sign-in where the service supports security keys, subject to each service policy
  • DUAL INTERFACE: Works by NFC tap over ISO 14443 or a contact card reader over ISO 7816, an NFC smart card that is not a USB device
  • CERTIFIED SECURE ELEMENT: NXP JCOP 4.5 (P71D600) with Common Criteria EAL6+ (augmented), backed by a 2 year warranty
Rank #3
Sale
K7 Ultimate Security Infiniti Antivirus 2026 for Lifetime Validity | 5 Devices | Threat Protection,Internet Security,Mobile Security| laptop,PC, Mac®,Phones,Tablets,iOS | 2 hr Email Delivery
  • Lifetime Protection : Safeguards your laptop, PC’s, Macs, tablets, and smartphones Lifetime against Viruses, Malware, ransomware, Spyware, Phishing and ensures secure browsing for a lifetime
  • Digital Freedom for Lifetime: Work, surf, bank, and shop in complete confidence, Ultimate Security Antivirus provides Zero-day protection using our ultra-fast, incredibly intelligent Cerebro Scanning Engine.
  • Webcam Protection & Parental Control[Windows]: Prevents unauthorized applications and hackers from spying on you by blocking access to your webcam. K7 Ultimate Security Antivirus ensures kids’ privacy & safety on online by applying parental & privacy Measures.
  • Backup & Restore: Ultimate Security’s complete protection prevents loss of important data by enabling you to back up all data and restoring whenever you want [Windows]; backup and restore Contacts [Android, iOS].'For more details about product, please visit our official website.
  • EMAIL DELIVERY:Activation Key will be sent through email along with installation and activation instructions to your registered email ID within 24 hours

What should an organization do if Medusa hits?

  1. Activate incident response and protect evidence. Follow the organization’s incident-response plan, preserve useful investigative information, and coordinate containment and recovery decisions with the incident-response team.
  2. Report promptly. Contact the FBI’s Internet Crime Complaint Center (IC3) or a local FBI field office, or report to CISA through its Incident Reporting System or 24-hour Operations Center. Healthcare organizations can also contact HHS for assistance focused on patient impacts. Use the contact and reporting details in the joint advisory.
  3. Do not treat payment as a recovery guarantee. The agencies do not encourage paying a ransom: payment does not guarantee that systems or data will be restored, or that stolen information will not be disclosed, and may embolden further attacks. Their incident guidance explains this position.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.