CISA, FBI and HHS Update Joint Cybersecurity Advisory on Medusa Ransomware
Cybersecurity and Infrastructure Security Agency sent this bulletin at 08/18/2026 11:13 AM EDT
You are subscribed to Cybersecurity Advisories for Cybersecurity and Infrastructure Security Agency. This information has recently been updated and is now available.
CISA, FBI and HHS Update Joint Cybersecurity Advisory on Medusa Ransomware
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS) released an update to the joint Cybersecurity Advisory #StopRansomware: Medusa Ransomware. The advisory is part of an ongoing series detailing ransomware variants and threat actors. It provides technical details on Medusa ransomware activity, along with detection and mitigation guidance to help protect at-risk government and critical infrastructure organizations.
Medusa is a ransomware-as-a-service variant first identified in June 2021. As of April 2026, Medusa actors have impacted more than 500 victims across multiple critical infrastructure sectors, including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. Other victims include organizations in the medical, education, legal, insurance, technology, and manufacturing industries.
The updated advisory details how Medusa actors gain initial access through brokers, phishing, and exploitation of newly disclosed, unpatched internet-facing vulnerabilities. Medusa actors often use legitimate tools and living off the land techniques to evade detection. They may also leverage remote monitoring and management software and remote access services, including Remote Desktop Protocol, for lateral movement. Once inside a network, they use common utilities and tools to support credential access, data exfiltration, and ransomware deployment. Medusa uses a double-extortion model, encrypting systems and threatening to publish exfiltrated data if victims do not pay.
CISA, FBI, and HHS urge organizations to implement the advisory’s mitigations, including these key actions:
- Mitigate known vulnerabilities by ensuring operating systems, software, and firmware are patched and up to date within a risk-informed timeframe.
- Segment networks to restrict lateral movement from initially infected devices to other devices in the organization.
- Filter network traffic by preventing unknown or untrusted origins from accessing remote services on internal systems.
Read the joint advisory for indicators of compromise, incident response actions, mitigations, and other recommendations to protect your organization from Medusa. For more information on the #StopRansomware series, visit CISA’s Stop Ransomware webpage.
Please share your thoughts with us through this anonymous survey. We appreciate your feedback.
This product is provided subject to this Notification and this Privacy & Use policy.