Join our FREE personalized newsletter for news, trends, and insights that matter to everyone in America

Newsletter
New

Cisa Warns Medusa Ransomware Hit 500+ Organizations And Intensified Healthcare Targeting

Card image cap

CISA, the FBI, and HHS issued an updated joint advisory warning that **Medusa ransomware** operators have compromised more than **500 organizations** as of April 2026, with heavy targeting of **critical infrastructure** and especially **healthcare and public health** entities. The agencies said the group evolved from a closed operation into a **ransomware-as-a-service** model in 2023, using double extortion by stealing data before encrypting systems. Officials said Medusa actors can exploit newly disclosed vulnerabilities within 24 hours, and in some cases were observed abusing flaws up to a week before public disclosure. The advisory said Medusa gains access through **initial access brokers**, reportedly offering up to **$1 million** for exclusive access, and has exploited vulnerabilities including `CVE-2024-1709`, `CVE-2023-48788`, GoAnywhere MFT flaws, and `CVE-2026-1731`. Once inside, operators use living-off-the-land techniques, credential dumping, stolen or vulnerable drivers, and legitimate remote monitoring and management tools to disable security controls, move laterally, steal sensitive data, and encrypt networks. Authorities also described aggressive extortion tactics such as rapid-payment discounts and paid deadline extensions, while urging organizations to patch quickly, segment networks, enforce phishing-resistant MFA, maintain offline immutable backups, and monitor for unauthorized RMM activity.