On 18 August 2026 the FBI, CISA and the Department of Health and Human Services updated joint advisory AA25-071A on the Medusa ransomware operation. The revision incorporates FBI investigation material as of April 2026 and puts the victim count above 500 organisations across critical infrastructure sectors — medical, education, legal, insurance, technology and manufacturing. The February 2025 original said 300.
Medusa is a ransomware-as-a-service operation first identified in June 2021, running standard double extortion: encrypt, threaten publication, negotiate. Initial access arrives through brokers, phishing and newly disclosed vulnerabilities on internet-facing systems, with living-off-the-land techniques and legitimate remote-management software carrying the intrusion from there.
Two Hundred Victims Between Two Footnotes
Read as a data series rather than a warning, the advisory records an operation adding roughly two hundred victims in fourteen months while under active federal investigation and named in a public advisory. Being described did not slow it down.
That sits with the finding filed at 26-0810 on the Gunra advisory: agency advisories are what is available when the operators are out of reach, and their value depends on whether anyone patches or reconfigures after reading one. A count that rises between revisions is the closest thing to a measurement of that anyone publishes.
The Third Seal
HHS joining the FBI and CISA as a co-sealer is administrative on its face and substantive underneath. A health agency signs when its sector is where the harm lands, and the update describes Medusa affiliates expanding tactics against healthcare specifically.
The corpus has recorded all year what a ransomware event means inside a hospital — paper records, diverted ambulances, withdrawn applications. An advisory co-sealed by the health department is the same fact expressed as bureaucracy: the operation’s victims are increasingly organisations where the outage reaches patients.
What The Mundane Technique List Means
Nothing in the advisory describes a novel capability. Bought access, phishing, unpatched edge systems, remote-management tooling — every item is the ordinary machinery this database records in most files. An operation running on commodity technique reached five hundred organisations, which says more about the five hundred than about the operation.
Compiled from the updated joint advisory AA25-071A and reporting of it, listed below. Victim counts are the agencies’ figures as of the dates stated in each revision. No victim is named here; the advisory names none. Graded high. Corrections: corrections@forensicpost.com.