Desk live·
ForensicPost
Ransomware/Enforcement/File 26-0818

Updated Medusa Advisory Puts Victims Past 500, and HHS Joins the Signatories

The FBI, CISA and HHS updated the Medusa ransomware advisory on 18 August: more than 500 victims as of April 2026, against 300 in February 2025. The health department signing on is the detail that carries information.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetMedusa ransomware victims
ActorMedusa
S. Rosler9 min readConfidence: high3 sources reviewed

On 18 August 2026 the FBI, CISA and the Department of Health and Human Services updated joint advisory AA25-071A on the Medusa ransomware operation. The revision incorporates FBI investigation material as of April 2026 and puts the victim count above 500 organisations across critical infrastructure sectors — medical, education, legal, insurance, technology and manufacturing. The February 2025 original said 300.

Medusa is a ransomware-as-a-service operation first identified in June 2021, running standard double extortion: encrypt, threaten publication, negotiate. Initial access arrives through brokers, phishing and newly disclosed vulnerabilities on internet-facing systems, with living-off-the-land techniques and legitimate remote-management software carrying the intrusion from there.

Two Hundred Victims Between Two Footnotes

Read as a data series rather than a warning, the advisory records an operation adding roughly two hundred victims in fourteen months while under active federal investigation and named in a public advisory. Being described did not slow it down.

That sits with the finding filed at 26-0810 on the Gunra advisory: agency advisories are what is available when the operators are out of reach, and their value depends on whether anyone patches or reconfigures after reading one. A count that rises between revisions is the closest thing to a measurement of that anyone publishes.

The Third Seal

HHS joining the FBI and CISA as a co-sealer is administrative on its face and substantive underneath. A health agency signs when its sector is where the harm lands, and the update describes Medusa affiliates expanding tactics against healthcare specifically.

The corpus has recorded all year what a ransomware event means inside a hospital — paper records, diverted ambulances, withdrawn applications. An advisory co-sealed by the health department is the same fact expressed as bureaucracy: the operation’s victims are increasingly organisations where the outage reaches patients.

What The Mundane Technique List Means

Nothing in the advisory describes a novel capability. Bought access, phishing, unpatched edge systems, remote-management tooling — every item is the ordinary machinery this database records in most files. An operation running on commodity technique reached five hundred organisations, which says more about the five hundred than about the operation.

How we reported this

Compiled from the updated joint advisory AA25-071A and reporting of it, listed below. Victim counts are the agencies’ figures as of the dates stated in each revision. No victim is named here; the advisory names none. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. #StopRansomware: Medusa Ransomware (AA25-071A)CISA
  2. Medusa ransomware gang has hit over 500 organizations, CISA warnsHelp Net Security
  3. HHS Joins Federal Medusa Ransomware Advisory, Citing Healthcare as a Frequent VictimhealthsystemCIO
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary