CISA and the FBI updated their #StopRansomware advisory on the Medusa ransomware gang on August 18, warning that the group has shifted its focus to the healthcare sector and moves faster than most defenders patch.
The revised advisory, originally published in March 2025, says Medusa actors have hit more than 500 victims across critical infrastructure sectors as of April 2026, with medical organizations among the most affected industries. The group has been observed exploiting newly announced vulnerabilities within 24 hours of disclosure, and in some cases up to a week before public disclosure, according to the agencies, citing Microsoft research on Medusa’s use of unpatched software.
The gang drew national attention in April when it disrupted the University of Mississippi Medical Center, the state’s only children’s hospital, Level I trauma center, and organ transplant program. Since then, Medusa has not added new victims to its leak site, which researchers suggest may reflect increased law enforcement scrutiny.
The advisory details the group’s affiliate model, notes ransom demands are often based on publicly announced revenue, and describes a case where a victim was approached by a second Medusa actor claiming the negotiator had stolen the ransom already paid. Operators have used remote access tools including AnyDesk, Atera, ConnectWise, and N-able during intrusions, the FBI said.
For hospitals and health systems, the advisory reinforces that Medusa treats healthcare as a priority target and that patching speed is a direct defensive lever. CISA and the FBI recommend reviewing the advisory’s indicators of compromise and testing incident response plans against its tactics.