Search This Blog

Wednesday, August 19, 2026

HHS, FBI warn hospitals as Medusa ransomware tops 500 victims

 The FBI, Cybersecurity and Infrastructure Security Agency and HHS have updated a joint advisory warning that the Medusa ransomware group has hit more than 500 organizations, including hospitals, since 2021.

HHS joined CISA and the FBI as a co-author of the Aug. 18 advisory, originally published in March 2025, to add its perspective on Medusa’s targeting of the healthcare and public health sector, which the agencies called a frequent victim of the group. The update reflects FBI investigations through April 2026, up from over 300 confirmed victims in the original version.

Medusa operates as a ransomware-as-a-service model, recruiting initial access brokers with payments ranging from $100 to $1 million to breach victim networks, primarily through phishing and unpatched software vulnerabilities. The group exploits flaws including a ScreenConnect authentication bypass, a Fortinet EMS SQL injection bug, a Fortra GoAnywhere deserialization vulnerability and a BeyondTrust remote code execution flaw, according to the advisory.

Medusa actors use a double-extortion model, encrypting victim data while threatening to leak it publicly, and have in some cases demanded a second payment after initial ransom collection, a possible triple-extortion tactic. The agencies urge organizations to patch known vulnerabilities, require multifactor authentication, segment networks and maintain offline backups.

The advisory’s expansion to formally include HHS underscores federal regulators’ growing focus on ransomware groups that disproportionately target hospitals already strained by thin margins and legacy IT systems.

https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/hhs-fbi-warn-hospitals-as-medusa-ransomware-tops-500-victims/

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.