CISA has updated a joint Cybersecurity Advisory on Medusa ransomware with the FBI Cyber Division and the U.S. Department of Health and Human Services (HHS) to share new tactics, techniques, and procedures, and indicators of compromise identified through FBI investigations as recently as April 2026.
The advisory, part of the #StopRansomware series on variants and threat groups, details Medusa threat activity, along with detection, incident response, and mitigation guidance. Medusa is a ransomware-as-a-service variant that has impacted more than 500 victims across a range of critical infrastructure sectors and industries—including frequent attacks against the Healthcare and Public Health Sector. Medusa actors use a double-extortion model, encrypting victim data while threatening to publicly release exfiltrated information if ransom is not paid.
The update also addresses Medusa actors recruiting initial access brokers, as well as leveraging vulnerability announcements to identify unpatched common vulnerabilities and exposures to exploit, phishing, abusing legitimate tools, and employing living off the land techniques.
CISA urges organizations to take key actions to reduce risk:
- Mitigate known vulnerabilities within a risk-informed timeframe.
- Segment networks to restrict lateral movement.
- Filter network traffic to validate legitimate access to remote services on internal systems.
The original announcement can be found here.




