The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI) and U.S. Department of Health and Human Services have identified healthcare as a frequent Medusa ransomware victim even as they describe the operation as opportunistic rather than sector-focused.

Medusa is a ransomware-as-a-service operation first identified in 2021, with developers and affiliates using data encryption and theft to extort victims. The recent advisory says Medusa actors can use newly announced exploits within 24 hours.

Victim count surpasses 500

The revised advisory draws on FBI investigations through April 2026 and puts the Medusa victim count at more than 500 across a variety of critical infrastructure sectors. The March 2025 advisory counted more than 300 as of February 2025. Neither version gives a healthcare-specific total, so the figures do not show how much of that increase came from the sector.

The update also adds two vulnerabilities to Medusa’s known attack record: CVE-2025-10035 in Fortra GoAnywhere MFT and CVE-2026-1731 affecting BeyondTrust Remote Support and Privileged Remote Access. Both are rated critical by their vendors.

Citing Microsoft Threat Intelligence, the federal advisory says Medusa actors leverage newly announced exploits within 24 hours and have used exploits up to a week before public disclosure. The agencies say there is no indication Medusa develops its own zero-day or N-day vulnerabilities.

Microsoft tracks rapid exploitation pattern

Microsoft Threat Intelligence documented the same rapid exploitation pattern for Storm-1175, an actor it tracks deploying Medusa. Since 2023, Microsoft has observed the actor exploit more than 16 vulnerabilities, including an SAP NetWeaver flaw one day after disclosure.

It also observed the GoAnywhere flaw and a SmarterMail vulnerability being exploited about a week before public disclosure. In some intrusions, Storm-1175 moved from initial access to ransomware deployment within one day, although many attacks took five to six days.

The two newly cited flaws did not follow identical patch timelines. Fortra lists Sept. 11, 2025, as the vulnerability’s discovery date and published its advisory Sept. 18. Microsoft says Storm-1175 exploited the flaw one week before public disclosure.

BeyondTrust says it automatically patched its SaaS instances and systems with its update service enabled on Feb. 2, four days before public disclosure, and first observed an exploitation attempt Feb. 10. BeyondTrust said observed exploitation activity was limited to internet-facing, self-hosted systems where the patch had not been applied before Feb. 9.

Attackers abuse legitimate remote access tools

After entry, Medusa actors may choose remote access software already present in a victim environment to evade detection. The FBI identified the use of AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp and Splashtop. The advisory says the actors combine those tools with Remote Desktop Protocol and PsExec to move laterally and identify files for exfiltration and encryption.

Federal mitigation recommendations

The agencies recommend phishing-resistant multifactor authentication, prompt patching of internet-facing systems, network segmentation and offline, immutable backups. Healthcare organizations can also contact Health and Human Services at HHScyber@hhs.gov for incident support focused on reducing adverse patient impacts.

Personalized Feed
Personalized Feed