CISA, the FBI, and HHS updated their Medusa advisory with a victim count above 500 and new detail on how the ransomware group gets in. The agencies say Medusa has moved from a March 2025 tally of more than 300 victims to more than 500 as of April 2026, with healthcare and critical infrastructure still frequent targets.
The group pays access brokers anywhere from $100 to $1 million for footholds, then races to use newly announced exploits within 24 hours, sometimes before public disclosure. Once inside, Medusa leans on legitimate tools, remote monitoring and management software, and Remote Desktop Protocol to move around, steal credentials, exfiltrate data, and launch ransomware.
That makes the patch window part of the attack surface: if a box is exposed to the internet or sits behind managed-file-transfer and remote-access tools, the hit can come through someone else’s foothold before normal patch cycles finish. The reporting also shows Medusa is buying speed and reach instead of inventing fresh exploits, which is why disclosure-day risk now matters to operators beyond any single product.