OVER 500 critical infrastructure organizations have been impacted by Medusa ransomware, according to an FBI advisory. This advisory, updated on August 18, 2026, highlights Medusa's expansion and increased aggressiveness since its initial detection in 2021, particularly targeting the healthcare sector. The ransomware displays rapid exploitation techniques, leveraging vulnerabilities shortly after they are disclosed.
It employs stealth techniques for lateral movement in networks, utilizing legitimate software for its operations. Medusa's double-extortion model demands ransom for both file recovery and preventing data leaks. The FBI encourages organizations to enhance incident response capabilities and implement preventative measures.