Medusa Ransomware 500 Victims — What the CISA Advisory Means

Medusa ransomware 500 victims is now the official U.S. federal tally: CISA, the FBI and the Department of Health and Human Services updated their joint advisory on August 18, 2026, confirming the ransomware-as-a-service group has breached more than 500 U.S. critical infrastructure organizations since June 2021 — up from the 300-plus figure in their original March 2025 report.
What Happened
The updated advisory (an update to AA25-071A) uses FBI investigation data current as of April 2026. As of that date, Medusa actors had impacted more than 500 victims across U.S. critical infrastructure sectors including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services — plus additional victims in medical, education, legal, insurance, technology and manufacturing more broadly. That is the specific, U.S.-focused figure the three agencies are citing; it should not be confused with a separate, larger, global number.
Medusa ransomware 500 victims is the U.S.-specific figure worth anchoring on when briefing leadership, since global counts run higher. Independent leak-site tracking (ransomware.live) puts Medusa’s total worldwide victim count at 517 as of August 17, 2026, with Germany named alongside the United States, United Kingdom, Australia, India, France, Canada, Brazil and Italy as one of the notable target countries in Medusa’s broader global operations. That global figure is separate from, and should not be conflated with, the U.S.-specific number in the CISA/FBI/HHS advisory.
Medusa surfaced as a closed ransomware operation in June 2021. Activity picked up meaningfully in 2023, when the group launched its “Medusa Blog” leak site and adopted a double-extortion, ransomware-as-a-service model. Medusa developers recruit initial access brokers on cybercriminal forums and marketplaces, offering $100 to $1 million USD per engagement, with an option for brokers to work exclusively for the group.
Why It Matters
An advisory like this is a due-diligence data point, not a single-incident alert — and that is precisely why it deserves board-level attention rather than only a SOC ticket. A five-year-old ransomware-as-a-service operation that is still growing its confirmed victim count year over year, across sectors ranging from healthcare to financial services to government, is evidence that “we haven’t been hit yet” is not the same as “we are not a target.” For NIS2-scoped organizations in particular, an updated federal advisory naming specific sectors is exactly the kind of external threat-context documentation an auditor will expect to see referenced in a risk register.
The advisory’s own recommended mitigations connect directly to a theme DIESEC keeps returning to: Medusa affiliates, like most ransomware operators, are buying initial access through exactly the kind of unpatched, internet-facing exposure that shows up in nearly every CVE alert in this newsletter. Ransomware readiness is downstream of ordinary patch and exposure management, not a separate program.
What You Should Do Now
- Patch known exploited vulnerabilities first: the advisory explicitly calls out mitigating vulnerabilities in operating systems, software and firmware as the top priority — cross-reference your open CISA KEV items today.
- Segment your network: confirm that a single compromised host cannot reach every other system — Medusa affiliates rely on lateral movement after an initial foothold.
- Restrict untrusted access to internal remote services: audit which remote access and management services (RDP, VPN gateways, RMM tools) are reachable from untrusted networks and lock them down to known sources.
- Verify offline, tested backups exist for critical systems, and confirm the restore process has actually been tested in the last twelve months, not just documented.
DIESEC Perspective
We see the same root cause behind most Medusa-style intrusions we analyze: not a single dramatic zero-day, but a patch or exposure gap that sat unaddressed for weeks or months before an initial access broker found it and sold the door in. The advisory’s mitigation list reads like a checklist of things most organizations believe they already do — the gap is usually between “documented policy” and “verified in production.”
Not sure whether your network segmentation and patch verification process would actually hold up against a Medusa-style intrusion? Contact DIESEC for a rapid ransomware exposure assessment.
Sources: CISA/FBI/HHS Joint Advisory (AA25-071A) | BleepingComputer
Published: 2026-08-21 | Category: Ransomware & Extortion | ~4 min read

