The Medusa ransomware-as-a-service operation has claimed more than 500 victims in critical infrastructure sectors, including frequent attacks against the healthcare and public health sector, according to an updated cybersecurity advisory issued by CISA, the Federal Bureau of Investigation and the Department of Health and Human Services.
Medusa Ransomware Operation
Medusa emerged in June 2021 as a closed ransomware group. Its developers initially handled the operation, including ransomware development, campaigns, and negotiating ransom. In early 2023, Medusa changed to a ransomware-as-a-service model that uses affiliates to conduct attacks in exchange for a percentage of ransom payments. The group also launched a data leak site in 2023 and adopted double extortion tactics. Under the RaaS model, Medusa threatens to publish stolen information while also seeking payment for decryption keys. The updated advisory states that attacks increased substantially after the group adopted this model.
When the cybersecurity advisory was first issued in March 2025, Medusa had already conducted over 300 attacks against critical infrastructure entities between 2021 and February 2025. The group has since claimed more than 500 critical infrastructure victims. Medusa claimed more than 200 victims in critical infrastructure sectors in a little over a year after its RaaS transformation, compared with 300 victims during the previous four years.
Affiliate Structure and Initial Access
Medusa affiliates receive different levels of control based on their experience and profitability. Newer and less experienced affiliates receive lower levels of trust, with the developers retaining control over certain campaign activities, including ransom negotiations. The operation also recruits initial access brokers on cybercriminal forums. These brokers provide access to victims’ networks. Payments to initial access brokers typically range from $100 to $1 million.
Attacks on the Healthcare and Public Health Sector
Medusa has frequently attacked HIPAA-covered organizations in the healthcare and public health sector. Some ransomware-as-a-service groups maintain policies against attacking healthcare organizations, but Medusa does not follow such a policy. The group is known to operate opportunistically by targeting organizations with unpatched software vulnerabilities that can be exploited remotely. A high percentage of Medusa victims is from the healthcare and public health sector.
How the Medusa Attack Method Works
Medusa attacks typically begin through phishing or exploitation of unpatched vulnerabilities. The group incorporates recently announced vulnerabilities into its attack arsenal, for example, the CVE-2026-1731 BeyondTrust vulnerability and the CVE-2025-10035 Fortra GoAnywhere vulnerability. The authoring agencies observed Medusa incorporating new exploits within 24 hours after a vulnerability was announced. In some cases, the group began exploiting vulnerabilities during the week before an announcement.
There is no evidence that Medusa develops its own exploits. The group likely obtains exploits from unknown sources, probably including initial access brokers, and use them before organizations have time to apply patches. Medusa actors also employ living-of-the-land techniques. These techniques allow the conduct of malicious activity through legitimate tools used for credential access, data exfiltration, and ransomware deployment. Medusa also conducts its own remote monitoring, manages its software for remote access services such as Remote Desktop Protocol during attacks.
Recommended Security Measures for HPH Organizations
Organizations in the healthcare and public health sector should rapidly mitigate known vulnerabilities and keep software, firmware, and operating systems patched and up to date.
Networks segmentation should be implemented to limit lateral movement inside the network. Networks should also filter traffic to stop unknown or untrusted origins from accessing remote services on internal systems.
The updated cybersecurity advisory identifies these measures in response to Medusa’s use of phishing, vulnerability exploitation, legitimate administrative tools, remote monitoring and management software, and remote access services.