CISA updates the Medusa advisory, more than 500 organisations hit

CISA, the FBI and the US Department of Health and Human Services published an update on 18 August 2026 to their joint advisory on Medusa ransomware, known by the code AA25-071A. Medusa was first identified in June 2021 and operates as a service, meaning those who build the ransomware rent it out to others who carry out the attacks. As of April 2026 the actors have hit more than 500 organisations, including in healthcare, the defence industrial base, critical manufacturing, government services, information technology and financial services. The advisory states that the actors obtain access through access brokers, phishing and exploitation of newly disclosed, unpatched internet facing vulnerabilities.

What happens technically

The service model explains much of the pattern. When the ransomware is rented out, there is not one actor with one method, but many affiliates each with their own. What they share is the encryption and the extortion apparatus. The routes in that the advisory highlights are therefore the cheapest ones available. An access broker is an actor who breaks in and sells the foothold onwards, so that whoever runs the ransomware operation does not have to obtain access themselves. Phishing and unpatched internet facing systems make up the rest. What all three have in common is that they require nothing new or unknown.

After the foothold, the advisory describes an approach that is hard to separate from ordinary operations. The actors use legitimate tools and living off the land techniques, meaning they work with what is already present on the machine. They take up remote monitoring and management software and remote access services, including Remote Desktop Protocol, to move further into the network. Common utilities are then used for credential access, data exfiltration and ransomware deployment. The extortion is double, meaning systems are encrypted while the actors threaten to publish the data they took. CISA, the FBI and HHS single out three measures. Known vulnerabilities should be patched within a risk informed timeframe, networks should be segmented so that an infected device cannot reach the rest, and traffic should be filtered so that unknown or untrusted origins cannot reach remote services on internal systems.

Access brokerphishing or an open flawFoothold in the networkremote management and RDPData taken outcredentials and filesEncryption and demandthreat of publication
Figure: The data leaves before the encryption starts. That is why the backup alone does not end the case, and why the demand arrives even once operations are restored.

What this means for your organisation

What makes Medusa relevant to your organisation is not the name, but the model. Double extortion means the backup solves half the problem. The data has already left the building when the encryption starts, and restoring it does not remove the demand that follows about not publishing it. If the data holds personal information, this is a personal data breach with a duty to notify the supervisory authority within 72 hours, and in serious cases a duty to notify the individuals as well. The decision on whether to pay is therefore not a technical decision, and it should not be taken for the first time under pressure.

The sector list in the advisory is worth reading closely. Healthcare, critical manufacturing, government services and finance are all sectors covered by NIS2, where Article 21 sets requirements for vulnerability handling and preparedness alike, while Article 23 governs incident reporting. Our assessment is that the most underrated item in the advisory is remote management tooling. Most organisations have more of it running than they think, often installed by a supplier for one specific purpose, and it grants exactly the kind of access these actors look for.

Berigo recommends

  • Patch known exploited vulnerabilities first, and use the CISA catalogue of those vulnerabilities as the priority list.
  • Map every remote access and remote management solution, including your suppliers', and shut down those not in active use.
  • Segment the network so a compromised client cannot reach servers directly, and filter access to internal remote services.
  • Prepare for double extortion, meaning data leaving before the encryption, with legal counsel, the data protection officer and communications involved.
  • Rehearse restoration from backups that cannot be altered from the production environment, and measure how long it actually takes.

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch