Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
WASHINGTON, D.C. — August 18, 2026 — Federal cybersecurity authorities have identified more than 500 victims of Medusa ransomware as the group continues targeting organizations through rapidly exploited vulnerabilities, stolen credentials and legitimate remote-access software.
The Cybersecurity and Infrastructure Security Agency and the Federal Bureau of Investigation disclosed the updated victim count in a revised joint cybersecurity advisory originally released in March 2025 with the Multi-State Information Sharing and Analysis Center.
As of April 2026, Medusa ransomware actors had affected more than 500 organizations. The previous federal count identified more than 300 victims through February 2025, representing an increase of more than 200 identified victims.
Many affected organizations operate within critical-infrastructure sectors. Federal authorities said Medusa has placed substantial attention on healthcare while also targeting education, legal services, insurance, technology and manufacturing organizations.
Medusa ransomware was identified in June 2021 and initially operated as a closed criminal group. The operation shifted to an affiliate model in 2023, allowing additional cybercriminals to conduct intrusions using Medusa ransomware infrastructure.
Access granted to affiliates can depend on their experience, earnings and demonstrated ability. Core Medusa operators may retain control over important parts of an attack, including ransom negotiations, when working with new or less experienced affiliates.
CISA and the FBI warned that Medusa actors can begin exploiting newly announced vulnerabilities within 24 hours of disclosure. Investigators have also observed the group using exploits as much as one week before a vulnerability was publicly disclosed.
Federal authorities have not identified evidence that Medusa operators independently develop zero-day or recently disclosed vulnerabilities. The group appears to obtain advanced access to exploitation methods from unknown sources or move rapidly after technical information becomes available.
The speed of exploitation reduces the time available for defenders to test and install security updates. Internet-facing systems, remote-management platforms and unpatched services can remain exposed during the period between public disclosure and completed remediation.
Medusa actors also obtain credentials before deploying legitimate remote monitoring and management software. These applications can blend into normal administrative activity because they are designed for authorized technical support and system maintenance.
The remote-access products observed during Medusa intrusions include AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp and Splashtop. Their presence does not establish malicious activity by itself. Organizations must determine whether each installation was authorized, who created the connection and what actions occurred during the remote session.
Once access is established, Medusa actors can steal data, disrupt operations and encrypt systems. The theft of information creates pressure beyond restoring affected devices because attackers can threaten to release sensitive files even when an organization possesses functioning backups.
The group researches potential victims before issuing ransom demands and may use publicly reported revenue to calculate the amount demanded. Victims can receive a reduced demand if payment is completed within a shorter period.
Medusa’s extortion system has also offered victims the option of paying $10,000 to extend the publication deadline by one day. Paying for additional time does not restore systems, confirm deletion of stolen information or guarantee that the attackers will honor the agreement.
Medusa removes an organization’s information from its public leak site after a ransom is paid, but CISA and the FBI warned that victims cannot verify whether the stolen data was permanently deleted.
FBI investigators documented one incident in which a victim was contacted by a second Medusa actor after paying a ransom. The second actor claimed that the original negotiator had stolen the payment and demanded half of the ransom again in exchange for what was described as the true decryptor.
Federal authorities said the incident could represent triple extortion, internal fraud among participating criminals or a lack of operational control within the ransomware network. The case demonstrates that payment to one participant does not ensure cooperation from other people connected to the operation.
Medusa recruits affiliates and access providers through cybercriminal forums. The organization has offered payments of up to $1 million to initial-access brokers willing to work exclusively for the group.
Initial-access brokers specialize in obtaining unauthorized entry into organizational networks and selling that access to other criminals. This division of labor allows ransomware operators to concentrate on data theft, encryption and extortion while another participant handles the original compromise.
CISA and the FBI urged organizations to prioritize security updates for Internet-facing systems, require multifactor authentication, review remote-access software and maintain protected backups that cannot be reached from the primary network.
Administrators should inventory authorized remote-management products and remove unnecessary installations. Security teams should monitor for newly installed tools, unexpected administrative sessions, unfamiliar service accounts and connections originating from unapproved locations.
Organizations should also segment critical systems, restrict administrative privileges and preserve security logs capable of showing account activity, remote sessions, file access and movement between systems.
Backups should be stored offline or separated from production credentials and tested regularly. A backup that remains accessible through a compromised account can be deleted or encrypted during the same intrusion affecting the primary environment.
The FBI and CISA do not encourage ransom payments because payment does not guarantee data recovery, prevent publication or confirm deletion of stolen material. Payment can also finance future attacks and create additional demands from other participants in the operation.
Organizations affected by Medusa ransomware should isolate compromised systems, preserve forensic evidence and report the incident promptly to federal authorities. Rapid reporting can support victim identification, infrastructure tracking and the collection of information needed to disrupt future attacks.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



