CISA, the FBI and the Department of Health and Human Services have issued a joint advisory on Medusa, and the headline figure is that the operation has hit more than 500 US critical infrastructure organisations as of April 2026.

The comparison is what makes it worth reading. The previous joint advisory, in March 2025, counted more than 300.

Where the victims are

The advisory names Healthcare and Public Health, the Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services — with further victims across medical, education, legal, insurance, technology and manufacturing.

HHS co-signing it is the tell. A health department does not join a ransomware advisory over data theft; it joins when hospitals are the sector taking the hits, and when the outcome being managed is care delivery rather than confidentiality.

The number that actually explains the growth

Medusa recruits initial access brokers on criminal forums, and the advisory puts the payments at $100 to $1 million for exclusive access.

Read that range rather than the top of it. The floor is $100 — the price of a single valid credential from an infostealer log, bought in bulk by someone who will sort out later whether it leads anywhere. The ceiling is seven figures for exclusive access into an organisation worth that much.

This is what a mature criminal supply chain looks like, and it is why patching advice keeps missing. Medusa's affiliates frequently are not breaking in. Somebody else already did, months ago, and sold the result. The intrusion you are defending against may have started with a laptop infected by something like the macOS stealer taking Keychain material and AWS keys, harvested by an entirely different crew.

Not a gang, a business model

Medusa appeared in January 2021 as a closed operation, and accelerated in 2023 when it launched a leak site and adopted data-theft extortion alongside encryption.

Then it became ransomware-as-a-service with an affiliate structure, which is the same arc Gunra followed to its own CISA and FBI advisory and the reason Qilin drove July's surge. The brand is a franchise. The people executing intrusions rent it, and — as the Ransom Busters research showed — the same affiliate frequently works under several brands at once, which makes victim counts by brand a weaker signal than they look.

The advisory is four months behind

The count is current as of April 2026 and is being published in August.

That lag is not a criticism of the agencies — verifying 500 victims across six sectors takes what it takes — but it does mean the number is a floor, not a total. Whatever Medusa did between April and now is not in it.

What the agencies recommend

The advisory's own list is short and unglamorous: patch operating systems, software and firmware; segment networks to restrict lateral movement; block untrusted access to internal remote services.

Two of those three are about limiting what an intruder can do after they are in, which is the correct emphasis for a threat whose entry point was bought rather than found. If the initial access is a valid credential someone else stole, the perimeter was never the control.

What to do beyond the advisory

  • Assume valid credentials, not exploits. Alert on impossible travel, new device enrolments and first-time-seen admin actions, because those are what a purchased login looks like.
  • Segment, then test the segmentation. Most networks are segmented on a diagram.
  • Restrict internal remote services — RDP, SSH, RMM and management interfaces — to jump hosts. This is the specific control the advisory calls out.
  • Rehearse the healthcare version of the question. If you are a hospital, the plan that matters is how you keep treating patients for a week without the systems, and that is not an IT plan.
  • Check your own infostealer exposure. If a staff credential is in a log being sold, you are already in someone's inventory.

What is not established

  • The current victim count. The number is a snapshot from April.
  • How many paid. Not reported, and leak sites list the ones who did not.
  • Who the affiliates are. The advisory describes the structure, not the people.
  • How much of the 300-to-500 growth is new activity rather than better visibility into activity that had already happened.