Medusa Ransomware (CISA AA25-071A, updated Aug 18, 2026): 500+ victims, 24-hour exploit window and what healthcare & manufacturing should do in 30/90 days
> Meta_title (EN): „Medusa ransomware: 500+ victims, 24h exploits — 30/90-day plan" (61 zn.)
> Meta_title (PL reference, above): 57 zn. ✓
> Meta_desc (EN): „Updated CISA/FBI/HHS advisory (AA25-071A): Medusa RaaS, 500+ victims, mainly healthcare. 24h exploits. 30/90-day actions." (128 zn.)
> AI-citation class: A. VerificationStatus: verified-primary-source. Update date: 2026-08-18.
BLUF
On 18 Aug 2026 CISA, FBI and HHS updated advisory #StopRansomware AA25-071A on Medusa — a RaaS that as of April 2026 has hit over 500 victims, mainly healthcare. Medusa weaponises new flaws within 24 hours, sometimes a week before disclosure. For NIS2 essential/important entities this means three obligations: fast KEV patching, network segmentation with offline immutable backups, and 24/72-hour reporting to the national CSIRT. We are not a 24/7 SOC, do not issue legal opinions, do not declare NIS2/KSC compliance. Below: facts, conclusions and a 30/90-day plan.
Key facts
- Source and date. Joint Cybersecurity Advisory AA25-071A was first published on 12 March 2025 and updated on 18 August 2026 by the FBI, CISA and HHS (US Department of Health and Human Services). The update includes TTPs and IOCs from FBI investigations up to April 2026 and an expanded list of exploited vulnerabilities [1][2][3].
- Scale and sectors. As of April 2026, Medusa has impacted more than 500 victims across critical infrastructure sectors; CISA previously reported 300 victims (2025). Healthcare and Public Health remains a frequent target, alongside critical infrastructure and local governments [1][2][3].
- 24-hour exploit window. Medusa leverages newly announced exploits within 24 hours and has been observed using exploits up to a week before public disclosure. The group does not develop its own zero-days — it obtains advanced access to exploits from unknown sources or quickly uses freshly disclosed vulnerabilities before victims can patch [1][2].
- RaaS and affiliate model. Since 2023 Medusa operates as RaaS — selling ransomware to affiliates with varying experience; ransom negotiations are often centrally controlled by the developers. It recruits initial access brokers (IABs) on cybercriminal forums, paying from $100 up to $1 million, including for exclusive work [1][2].
- Vectors and tooling. Initial access via phishing and exploitation of unpatched vulnerabilities (incl. ScreenConnect CVE-2024-1709, Fortinet EMS CVE-2023-48788, Fortra GoAnywhere CVE-2025-10035, BeyondTrust CVE-2026-1731). For evasion it abuses legitimate remote software: AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, Splashtop, plus RDP and PsExec [1].
- Potential triple extortion. The FBI described an incident where a victim was contacted by a separate Medusa actor claiming the negotiator had stolen the already-paid ransom and asking for half again for the "true decryptor" — indicating possible triple extortion or internal dysfunction [2][4].
- Victims and leak-site silence. After the attack on the University of Mississippi Medical Center (the state's only children's medical centre, only Level I trauma center and only organ transplant programme), no new victims have appeared on the leak site since April 2026, which some experts link to increased law-enforcement attention [2][5].
- NIS2 implication. Medusa is a textbook example of RaaS ransomware risk for manufacturing and healthcare: a 24-hour exploit window versus patch time, RMM remote tools as a lateral-movement vector, and double (and potentially triple) extortion. Essential/important entities report under art. 23 NIS2 (24h early warning → 72h notification); BCP/DR obligations flow from art. 21(2) [1][6].
- Sources (6). CISA AA25-071A [1], The Record [2], IC3 CSA PDF [3], BleepingComputer (300+ critical infrastructure) [4], SC World UMMC [5], BleepingComputer Microsoft/Storm-1175 [6].
> Methodology note: facts [1] come from the official joint advisory (class A). Operational conclusions (NIS2 mapping, 30/90-day plan) are CHORS recommendations and are not part of the advisory. Recommendations for a specific firm require that firm's own context (segment, suppliers, exposure).
Decision table: what we know → what it means for B2B/manufacturing → what to do
| Area | What we know (facts from advisory + research) | What it means for a B2B / manufacturing firm | Recommended 30-day action | Recommended 90-day action |
|---|---|---|---|---|
| Patch window | Medusa exploits new flaws within 24h, sometimes up to a week before disclosure [1][2] | Time between CVE publication and real patching is now shorter than many firms' patching cycle | Subscribe to CISA KEV and vendor alerts; critical-patch SLA ≤48h; asset and software inventory | Authorized Vulnerability Assessment (P1) on a quarterly cycle; patch-management automation |
| Backups / BCP | Double and potentially triple extortion; no guarantee data is deleted after payment [1][2] | Even after backup recovery, data may be published; forces a "pay or cease to operate" decision | Offline immutable backups in a separated location; restore test of one critical machine; BCP/DR plan | Continuous restore testing (RPO/RTO), automation; AD/IdP-isolated backup segment; crisis-communication plan |
| RMM / remote tooling | Medusa abuses legitimate RMM tools (AnyDesk, ConnectWise, N-able, BeyondTrust, etc.) for evasion [1] | Legitimate remote tools in your environment are a potential affiliate vector | Inventory all remote/RMM tools; restrict access; monitor remote sessions; MFA for RMM | Privileged Access Workstation (PAW) model; anomaly monitoring of remote sessions; IT supply-chain policy (art. 21(2)(d)) |
| Network segmentation | CISA recommends segmentation to limit lateral movement from infected hosts [1] | Shared AD/IdP domains and no IT/OT segmentation widen the encryption blast radius | Map Tier-0/Tier-1/Tier-2; VLANs; restrict service accounts | Purdue model + jump-host; passive monitoring on the IT/OT boundary (no active OT scanning) |
| NIS2 reporting (art. 23) | 24h early warning from "becoming aware" of a potential incident; 72h notification [1][6] | No reporting procedure = delay and loss of regulator trust | Incident playbook; appoint national-CSIRT contact; early-warning template | Quarterly tabletop exercise (ransomware simulation); established communication channels with the national CSIRT |
| Vulnerabilities listed | ScreenConnect CVE-2024-1709, Fortinet EMS CVE-2023-48788, GoAnywhere CVE-2025-10035, BeyondTrust CVE-2026-1731 [1] | Specific remote products are actively exploited by Medusa | Immediately verify versions and patch these products (screenconnect, fortinet ems, goanywhere, beyondtrust) | Periodic KEV-based patch review; continuous vulnerability-monitoring process |
Operator perspective: Marcin Białczyk (CHORS.NET)
The most worrying signal in this update is not the victim count but the tempo: Medusa can weaponise a freshly disclosed vulnerability within 24 hours, sometimes before the vendor has even publicly disclosed it. In my operational practice I see many firms treating patching as a "once a quarter in a maintenance window" activity. That model assumed attackers needed weeks to build exploits — an assumption that is no longer valid. If the time between CVE publication and real remediation in your firm is measured in weeks, then the window Medusa (and other RaaS families) exploits is wide open. That is why in the benchmarks I run for clients we target a critical-patch SLA from the CISA KEV list of ≤48 hours, and treat key remote products (screenconnect, fortinet ems, goanywhere, beyondtrust) as priority.
The second point I always raise with ransomware is legitimate remote tooling. Medusa does not "brute-force" its way in — it uses AnyDesk, ConnectWise, N-able, BeyondTrust or Splashtop, exactly what many operators and MSPs have deployed permanently for remote support. That is a classic vector: if you have an RMM tool on your network, you also have a path an affiliate can use to get inside and move laterally. Within our P0 (Passive Exposure Snapshot) we show clients which endpoints and remote tools actually "shine" in OSINT and telemetry — without active contact with the infrastructure. The recommendation for a publicly visible RMM without MFA is binary: secure it or shut it down.
The third axis is that healthcare and manufacturing are targets, not accidents. The advisory explicitly names Healthcare and Public Health as a frequent target, and the University of Mississippi Medical Center attack — the state's only children's centre and only transplant programme — shows the consequences are not just data loss but loss of operational capability. For manufacturers and hospitals, where downtime is a real risk to people and continuity, the key is that backup and BCP plans are tested, not merely present. Do not ask "do we have backups" — ask "are the backups immutable, separated from AD, and have we tested the restore". That is the difference between a week-long stop and months of operational loss.
> `[[TU DOPISZ]]` (case study placeholder, e.g. "FMCG manufacturer, 400 endpoints, an RMM tool exposed remotely without MFA; after P0 + P3 readiness consultation, RMM secured with MFA in 7 days, critical KEV patch deployed within 30 days, immutable backup tested in 60 days."). Without a real case, no fabrication.
FAQ
Can Medusa attack my company even if I am not in healthcare or critical infrastructure?
Yes. Medusa operates opportunistically, targeting victims with unpatched software regardless of sector — the advisory covers critical infrastructure, local governments, manufacturing, and victims include financial services and others. Sector is not the filter; the filter is whether you have unpatched vulnerabilities and/or remote tooling accessible without strong controls.
How fast do I really need to react to new vulnerabilities?
Medusa can use a newly announced exploit within 24 hours, and has been observed using flaws up to a week before public disclosure. That means critical patching should be measured in hours/days, not weeks — especially for remote products (RMM, VPN, gateways). Subscribing to CISA KEV and vendor alerts is the minimum.
Does CHORS.NET confirm NIS2/KSC compliance as a result of this article?
No. CHORS.NET does not certify NIS2/KSC compliance and does not issue standalone legal opinions; we are not a 24/7 SOC and we do not guarantee detection of every incident. We collaborate with law firms on legal interpretation and support clients under P3 NIS2/KSC Readiness (gap assessment, control matrix, evidence pack).
What should I do immediately if I see encrypted files and a ransom demand?
(1) Isolate affected hosts (disconnect from the network, do not power off); (2) preserve logs (memory, disk, EDR telemetry); (3) appoint an internal contact and trigger escalation; (4) send early warning to the national CSIRT within 24 hours; (5) do not pay the ransom without an impact analysis and without consulting a law firm and the relevant authority — in some jurisdictions payment may breach sanctions; (6) trigger the crisis communication plan.
Does CHORS.NET run authorised security tests as a standard offering?
In our nomenclature (P1 — Authorized Vulnerability Assessment, with the Exposure Validation component) we run authorised validation within an agreed scope (AtT + RoE + manifest), never without a signed package and capability tokens. Full scope: /uslugi/.
CTA (internal links)
- CHORS.NET services — P0/P1/P2/P3 — what we do, and what we deliberately do not do.
- CHORS NIS2/KSC — readiness, gaps, 30/90/180-day plan — P3 Readiness.
- AI policy in cyber operations — how we use (and do not use) AI in IR.
- How CHORS.NET works — operator brief — methodology, boundaries, agent roles.
Boundaries and assumptions
- We are not a 24/7 SOC and we do not guarantee detection of every incident. This article describes a class of risk and a general framework — it is not a detection service.
- We do not certify NIS2/KSC compliance and we do not issue standalone legal opinions. On legal interpretation we collaborate with law firms.
- Results reflect the state of the art on 2026-08-18. Ransomware families evolve (TTPs, IOCs, victim list); recommendations require at least quarterly review.
- We do not provide generic one-size-fits-all checklists. Every 30/90-day plan requires a specific firm's context: NIS2 segment classification, exposure (public RDP/VPN/RMM), MSP suppliers, data classification, IT/OT topology.
- This article is informational and technical. It is not legal advice or an investment recommendation.
- For interpretation of NIS2/KSC (art. 21, art. 23) we refer to counsel. The article references above are framework-level and require legal verification against the specific facts.
- In OT/ICS we apply a passive approach. We do not actively scan PLC/HMI/SCADA; our P2 support is passive evidentiary support and configuration hardening.
Data aktualizacji: 2026-08-18
Update date: 2026-08-18
Data aktualizacji: 2026-08-18
Update date: 2026-08-18
