Circuit Wire — a daily news update from the Circuit.
The FBI, CISA and the Department of Health and Human Services updated their joint Medusa ransomware advisory on August 18, raising the confirmed victim count above 500 organizations. The advisory, catalogued as AA25-071A, was first published in March 2025 with a figure of more than 300 victims. The new total reflects forensic work through April 2026.
The agencies list the affected sectors as healthcare and public health, the defense industrial base, critical manufacturing, government services and facilities, information technology, and financial services. Victims also include organizations in medical, education, legal, insurance, technology and manufacturing work. The advisory covers activity going back to when Medusa was first identified in June 2021.
Medusa runs as a ransomware-as-a-service operation. Its developers recruit initial access brokers on criminal forums and marketplaces, offering payments between $100 and $1 million for a way into a target network, with the option of working for Medusa exclusively. Those brokers rely on phishing for credentials and on unpatched internet-facing software, including a ScreenConnect authentication bypass and a Fortinet EMS SQL injection flaw.
Once inside, the group blends in. Operators use PowerShell and the Windows command prompt for enumeration, and they turn to commercial remote management software already common in corporate environments. The advisory names AnyDesk, Atera, ConnectWise, eHorus, N-able, PDQ Deploy, PDQ Inventory, SimpleHelp and Splashtop. Investigators have also seen the group attempt to disable endpoint detection tools using vulnerable or signed drivers, and delete PowerShell command history to slow down responders.
Data is pulled out with Rclone before the encryptor runs. Files are renamed with a .medusa extension, backups and shadow copies are destroyed, and virtual machines are shut down and encrypted by hand.
The extortion side is unusually structured. Victims are told to make contact within 48 hours through a Tor chat page or the encrypted messenger Tox. Those who stay silent get a phone call or an email. Names are then posted to a leak site alongside a countdown clock and a ransom figure, with the stolen data advertised for sale before the timer runs out. A victim can pay $10,000 to add a single day to the clock.
The advisory also records one case that points to a third layer of pressure. After a victim paid, a separate Medusa actor made contact claiming the negotiator had stolen the money and asking for half the sum again in return for the real decryptor.
The three agencies repeated the same three priorities they set out last year, as reported by BleepingComputer: patch known vulnerabilities, segment networks to limit lateral movement, and block untrusted origins from reaching remote services on internal systems.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

