Medusa Ransomware Expands Victim Count with New Tactics

Medusa Ransomware Expands Victim Count with New Tactics

First seen 18 Aug 2026, 21:10 UTC CyberscoopDatabreaches 89% similarity 69.5

Article Content

Browse articles
ThreatCluster

The Medusa ransomware group has increased its victim count from over 300 to more than 500 in just over a year, as reported in a U.S. government advisory. The group employs access brokers, paying them between $100 and $1 million to gain entry into networks. Medusa targets unpatched software vulnerabilities, particularly affecting the Healthcare and Public Health sector. Exploited vulnerabilities include flaws in Fortra GoAnywhere and BeyondTrust software. Medusa actors leverage legitimate tools and living off the land techniques to evade detection. They have been observed using exploits within 24 hours of their announcement. The advisory updates previous guidance from March 2025 and highlights ongoing FBI investigations into the group. Medusa is known for opportunistic attacks rather than targeting specific organizations.

Key Points: • Medusa ransomware has increased its victim count to over 500 in just over a year. • The group utilizes access brokers, compensating them significantly for network access. • Healthcare and Public Health sectors are frequently targeted due to unpatched vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2025-03-01
Initial advisory on Medusa ransomware released
The Cybersecurity and Infrastructure Security Agency published an advisory detailing Medusa's tactics and initial victim count of over 300.
Cyberscoop
2026-08-18
Updated advisory published
The U.S. government released an updated advisory indicating Medusa's victim count has risen to over 500 and detailing new tactics.
Databreaches
2026-08-18
Exploited vulnerabilities identified
The advisory lists vulnerabilities in Fortra GoAnywhere and BeyondTrust as targets for Medusa's attacks.
Cyberscoop

Community

Browse all →

Tracked Entities in This Story