Executive summary

CISA, the FBI and HHS released on August 18, 2026 an update of the joint #StopRansomware advisory AA25-071A on Medusa, raising the confirmed victim count above 500 critical infrastructure organizations, including providers and entities in the Healthcare and Public Health sector. The group, operating as a ransomware-as-a-service (RaaS) since June 2021, is accelerating: between March 2025 and April 2026 more than 200 additional victims are attributed, compared to the 300 accumulated in the prior four years.

The advisory adds updated TTPs confirmed by FBI investigations through April 2026, fresh IOCs (hashes, domains, IPs), and reinforced mitigations with emphasis on network segmentation, phishing-resistant MFA, and response to affiliates using vishing for initial entry.

Key points

  • Operator: Medusa (RaaS) since June 2021; transitioned to affiliate model in 2023 with double extortion (encryption + public leak site).
  • Confirmed victims: >500 organizations in critical infrastructure (vs. ~300 in ~4 years when the original advisory was published in March 2025).
  • Affected sectors: Healthcare and Public Health, Manufacturing, Government Services, Education, Information Technology, Financial Services.
  • Predominant initial vectors: phishing (T1566) and help-desk vishing (Scattered-Spider / Octo Tempest style), abuse of valid credentials and lateral movement.
  • Main TTPs:
    • T1486 – Data Encrypted for Impact
    • T1657 – Financial Theft (extortion)
    • T1059 – Command and Scripting Interpreter (PowerShell, cmd, WMI)
    • T1027 – Obfuscated Files or Information (packed binaries)
    • T1041 – Exfiltration Over C2 Channel
  • IOCs: .onion domains and mirrors on compromised legitimate hosts; updated C2 IPs in the advisory PDF.
  • Ransom: Bitcoin, 24-72h deadlines before publication on the “Medusa Blog” DLS.
  • Official CISA mitigations: network segmentation, FIDO2/WebAuthn MFA, AD/LDAP monitoring, just-in-time access, LOLBin hardening, token revocation, and tested response plans.

Technical analysis

Qualitative shift: closed RaaS to mature affiliate ecosystem

Medusa’s 2023 transformation (from closed group to RaaS with affiliate program) explains the exponential victim curve. The advisory describes three trust tiers based on history and profitability:

  1. Core affiliates — negotiation access, encryption key control.
  2. Intermediate affiliates — technical execution, no direct negotiation.
  3. Entry-level affiliates — initial intrusion only (IAB); the developer retains payload + leak site.

This tiering overlaps with the initial access broker (IAB) chain that sells access into Medusa. In healthcare this means a concrete risk: entry-level affiliates target hospitals with vishing-susceptible help desks, capture a privileged account, and either resell or directly exploit it. The FBI highlights help-desk vishing (impersonating an employee and forcing MFA reset) as a dominant 2026 vector.

Why healthcare is squarely in the crosshairs

  • High payment pressure: hospital downtime = measurable clinical risk (AEJ study: +34-38% in-hospital mortality during a ransomware attack). Healthcare victims pay faster.
  • Hybrid attack surface: cloud-hosted EHR + IoMT devices on segmented LANs + many remote vendors. Each link is an IAB candidate.
  • Regulatory asymmetry: HIPAA and the 2026 update require MFA, segmentation and vendor evaluation, but cloud vendors are rarely held accountable when the incident is at the customer.

High-fidelity indicators of compromise

The advisory lists SHA-256 hashes of Medusa samples, leak-site domains (.onion + mirrors), and IP ranges. Some have persisted since March 2025 — the group isn’t rotating infrastructure as fast as its affiliates. That allows reasonably stable reputation-based detection over months.

Regulatory implications

U.S. — HIPAA + HHS

  • The HIPAA Security Rule update (final rule expected August 2026) elevates network segmentation and continuous business associate assessment to required (not “addressable”) controls.
  • A Medusa breach at a covered entity triggers HHS-OCR notification (60 days) + media notice if >500 affected.
  • If the initial vector is vishing, §164.308(a)(5)(ii)(D) Password management and §164.312(a)(2)(i) Unique user identification are directly in non-compliance.

EU — NIS2 + MDR

  • NIS2 (Art. 21): healthcare entities are essential entities. Measures 6.e (MFA policies) and 6.j (access management) are mandatory since October 2024.
  • MDR Annex I §17.2: medical device manufacturers must demonstrate post-market cybersecurity. If an IoMT falls into a Medusa intrusion, the manufacturer must report a serious incident (Art. 87).
  • ENS (Spain) — HIGH category: if the hospital is an operator of essential services, ENS requires MFA on all administrative access and physical/logical segmentation of IoMT networks.

UK — DSPT + NHS Data Security

  • The NHS Data Security and Protection Toolkit requires mandatory anti-phishing training and vishing-specific incident testing aligned with DS2032 §4.

Recommendation

Immediate actions (72 hours)

  1. Hunt IOCs in the last 90 days — correlate against hashes, domains and IPs published in AA25-071A. Prioritize LDAP/AD, EDR, and help-desk reset logs.
  2. Audit MFA resets at help desk — vishing typically precedes ransomware by 1-4 weeks. Look for patterns: reset requested from external number with employee impersonation.
  3. Verify phishing-resistant MFA — remove SMS and TOTP where possible; migrate to FIDO2/WebAuthn for admins and help desk.
  4. Verify IoMT segmentation — clinical VLAN devices must be isolated from the administrative VLAN where ransomware moves.

30-day actions

  1. Tabletop ransomware exercises with vishing as initial vector — run simulations reproducing the full scenario: vishing → MFA reset → lateral movement → encryption.
  2. Review business associate cloud contracts — require notification in <24h and forensic audit rights.
  3. Implement just-in-time admin access — eliminate persistent privileged accounts.
  4. Validate DLS leak response plan — have communication templates ready before a leak surfaces.

Exposure indicators

  • Official hashes / IOCs: AA25-071A Appendix A and B (download the advisory PDF from CISA).
  • MITRE ATT&CK TTPs: T1566 (phishing), T1078 (valid accounts), T1486 (encrypt for impact), T1657 (financial theft), T1059 (command interpreter).

Source

Primary source: CISA #StopRansomware AA25-071A — Updated Aug 18, 2026


HealthSec · Editorial analysis on healthcare cybersecurity · healthsec.gutibot.com