Federal agencies have issued an urgent warning to the healthcare industry about the growing threat posed by Medusa ransomware attacks exploiting unpatched software systems.
The Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, and the U.S. Department of Health and Human Services jointly released an updated advisory on August 18, 2026, targeting the healthcare sector specifically.
The advisory builds on previous guidance and provides detailed tactics, techniques, and procedures alongside indicators of compromise to help organisations respond effectively and limit damage.
Medusa ransomware has been striking the healthcare space with particular force, though it is also actively targeting the defence industry, critical manufacturing, information technology, and financial services sectors.
Medusa operates as a ransomware-as-a-service variant, first identified in June 2021, and has since grown into a significant and well-organised criminal enterprise with broad reach.
Since its inception, Medusa developers and their affiliates have successfully hit over 500 victims, spanning “medical, education, legal, insurance, technology, and manufacturing” industries across multiple regions.
While Medusa originally operated as a closed organisation, since 2023 it has transitioned to an affiliate model, selling its ransomware-as-a-service to affiliates paid varying amounts based on experience and extortion effectiveness.
Medusa employs a double extortion strategy, deploying ransomware to encrypt victim data and then demanding payment both to decrypt the data and to suppress its public release.
The group actively recruits access brokers through cybercriminal forums and marketplaces, who then penetrate target organisations via phishing campaigns or by exploiting unpatched vulnerabilities in products including ScreenConnect, Fortinet, Fortra, and BeyondTrust.
The advisory lists specific indicators of compromise that organisations should review and block as a matter of priority, alongside detailed eviction countermeasures and broader mitigation strategies.
Security professionals are urged to apply these mitigations as soon as possible, given the speed at which Medusa affiliates move once initial access to a network is established.
The advisory reinforces how important it is to continue internal phishing tests, employee training, and patching programmes as priorities to help avoid becoming a victim.
Organisations operating in healthcare are considered especially vulnerable given the sensitivity of patient data, the operational pressures staff face, and historically slower adoption of cybersecurity best practices compared to other sectors.
The joint federal advisory represents a coordinated push to raise awareness and accelerate protective action across industries before Medusa affiliates can claim further victims.

