Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Medusa is a ransomware-as-a-service (RaaS) operation that combines file encryption with threats to publish stolen data. In a joint advisory updated August 18, 2026, the FBI, CISA, and HHS said Medusa developers and affiliates had affected more than 500 victims as of April 2026. The agencies describe double extortion as the documented pattern; one investigated account of a further payment demand does not establish that every attack follows a routine third extortion stage.

What is Medusa ransomware?

Medusa is a ransomware variant first identified in June 2021. The FBI, CISA, and HHS describe it as a ransomware-as-a-service operation: developers maintain the ransomware operation, while affiliates carry out campaigns. The agencies distinguish it from MedusaLocker ransomware and Medusa mobile malware, which are separate threats.

The operation began as a closed group in which one organization controlled both development and campaigns. By at least early 2023, it had shifted to an affiliate model. Affiliates’ trust and responsibilities can vary, and developers may handle ransom negotiations for less experienced affiliates.

Medusa has affected organizations across multiple critical infrastructure sectors and other industries. The advisory identifies Healthcare and Public Health as a frequently affected sector, but says the actors operate opportunistically around vulnerable software; Medusa is not limited to healthcare.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Smart Keeper USB-C Port Locks with Key, 4 Blockers 1 Key
  • Bundle: 4 locks + 1 key.
  • Easy to Use: It can be installed by hand.
  • All-Purpose Key: A common key can be used to unlock 9 different products within the Essential series.

How does Medusa get into a network?

The FBI, CISA, and HHS advisory updated August 18, 2026, describes several possible access routes. An incident may involve one or more of them; the advisory does not say that every Medusa intrusion uses the same sequence.

  • Phishing: A user may be tricked into opening a malicious attachment or link or otherwise providing access.
  • Unpatched vulnerabilities: Actors exploit vulnerable software, including internet-facing systems. The advisory associates activity with ScreenConnect CVE-2024-1709, Fortinet EMS CVE-2023-48788, Fortra GoAnywhere CVE-2025-10035, and BeyondTrust CVE-2026-1731. The latter two appear in the August 2026 update.
  • Access brokers: Criminal brokers may sell or provide access to organizations. The advisory describes broker offers ranging from $100 to $1 million; that is a reported offer range, not a typical fee or proof of what was paid in any particular incident.

The agencies report that Medusa actors may exploit a newly announced vulnerability within 24 hours and have used exploits up to a week before public vulnerability disclosure. These are reported behaviors, not a prediction that every newly disclosed flaw will be exploited or that every Medusa incident involves a zero-day vulnerability.

After gaining access, actors may map the network, seek credentials, move between systems, and prepare to deploy ransomware or steal data. The advisory documents use of PowerShell and Windows command-line tools, legitimate remote monitoring and management software, and Remote Desktop Protocol. It also describes data exfiltration and disabling security tools on some targets. These are observed techniques, not a fixed checklist for every intrusion.

What does double extortion mean?

In a double-extortion attack, criminals both encrypt systems or files and threaten to publish information stolen from the victim if the ransom is not paid. Encryption can disrupt operations; the leak threat adds pressure by putting confidential information, customer trust, and regulatory or contractual obligations at risk—even if an organization can restore its files.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Medusa operates a leak site that lists victims and uses countdowns to pressure them. The actors may also advertise stolen data for sale or threaten to list it as negotiation leverage. The advisory says Medusa actors claim to remove victim information after payment, but there is no way to verify that a payment results in deletion.

The advisory describes ransom notes demanding contact within 48 hours; that is a reported tactic, not a universal deadline. It also says victims can be offered a one-day extension of a leak-site countdown for $10,000 in cryptocurrency. This is a described extortion-site offer, not a validated service or a recommendation.

Does Medusa use triple extortion?

The agencies report one FBI-investigated case in which a victim that had already paid was contacted by a separate Medusa actor. The second actor claimed the negotiator had stolen the payment and asked for half again in exchange for the “true decryptor.” The advisory says this could indicate triple extortion or operational dysfunction and lack of cohesion. A single account does not show that a further payment demand is a standard stage of Medusa attacks.

How many victims has Medusa affected?

As of April 2026, Medusa developers and affiliates had impacted more than 500 victims, according to the FBI, CISA, and HHS joint advisory updated August 18, 2026. The count reflects the agencies’ investigations through April 2026; it is not a live total or a count of every unreported incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How can an organization prepare for a Medusa attack?

The agencies’ recommendations address different stages of an intrusion: preventing initial access, limiting what an intruder can reach, detecting activity, and restoring operations if systems are encrypted.

Reduce likely entry points

  • Patch operating systems, software, and firmware promptly. Prioritize known exploited vulnerabilities on internet-facing systems.
  • Use phishing-resistant multifactor authentication where possible, especially for webmail, VPNs, and accounts that can access critical systems.
  • Restrict remote access and filter traffic so unknown or untrusted sources cannot reach internal remote services.
  • Use long passwords, apply least privilege, and audit accounts for access that is no longer needed.

Limit spread and improve detection

  • Segment networks so a compromised account or device cannot freely reach every system.
  • Monitor network activity and review relevant logs for suspicious access, credential use, and movement between systems.
  • Know which remote access and remote management tools are authorized, so unexpected use is easier to identify.

Make recovery independent of compromised systems

Keep multiple copies of sensitive data and servers in a secure, segmented location physically separate from the systems they protect. The advisory recommends offline backups that are encrypted and immutable, along with regular backup and restoration practice.

An external hard drive or other storage device can support an offline copy, but a drive alone is not a backup architecture. It needs to be included in a secure plan, protected from routine network access, and tested through actual restoration exercises. A backup that cannot be restored when needed does not provide dependable recovery.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should an organization do if it suspects a Medusa intrusion?

Acting before encryption can reduce disruption, but the response should be based on evidence gathered from affected systems and the wider network.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Identify and isolate compromised hosts. Contain affected devices to limit further access and spread.
  2. Investigate and preserve evidence. Hunt for the intrusion and collect relevant logs and artifacts; use them to understand the scope and inform containment.
  3. Report the incident. The advisory recommends reporting to CISA and/or the FBI.
  4. Plan informed containment and eviction. Remove the actors’ access and address the compromised accounts, systems, or vulnerabilities identified during the investigation.
  5. If files are already encrypted, consult the agencies’ incident response checklist referenced in the joint advisory and coordinate recovery with the incident-response team.

The FBI, CISA, and HHS joint advisory, updated August 18, 2026, states: “The authoring organizations do not encourage paying ransom as payment does not guarantee victim files will be recovered.”

Quick Recap

Bestseller No. 1
Smart Keeper USB-C Port Locks with Key, 4 Blockers 1 Key
Smart Keeper USB-C Port Locks with Key, 4 Blockers 1 Key
Bundle: 4 locks + 1 key.; Easy to Use: It can be installed by hand.
$34.82

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.