On August 18, 2026, the FBI, CISA, and the Department of Health and Human Services issued an updated joint advisory warning that the Medusa ransomware-as-a-service operation has now hit more than 500 organizations — nearly double the count from last year. The victims aren't just hospitals and government agencies. Medusa affiliates are actively hitting law firms, insurance offices, IT shops, and small manufacturers — the exact profile of a lot of York County businesses. If you don't know whether your network is patched against the specific vulnerabilities they're exploiting, you're the kind of target they're looking for.
What the new advisory actually says
Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, according to an updated joint advisory from the FBI, CISA, and HHS that draws on FBI investigations conducted as recently as April 2026. That's up from the roughly 300 critical infrastructure organizations reported in the March 2025 version of the advisory.
Confirmed victim sectors include Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services, plus organizations in medical, education, legal, insurance, technology, and manufacturing industries. In plain English: if you're a small law firm, insurance broker, manufacturer, MSP, or medical practice, you are on this list.
Medusa was first identified in June 2021 and is a ransomware-as-a-service operation that transitioned to an affiliate-based model by early 2023, allowing developers to recruit external operators. That affiliate model is why the victim count keeps climbing — it's not one small crew, it's a franchise.
How Medusa affiliates are getting in
The advisory is specific about the front doors Medusa is kicking down. Medusa actors recruit initial access brokers on cybercriminal forums, reportedly offering between $100 and $1 million for access to victim networks, and they rely heavily on phishing and exploitation of unpatched internet-facing applications.
The named vulnerabilities they exploit include CVE-2024-1709 in ConnectWise ScreenConnect, CVE-2023-48788 (a Fortinet EMS SQL injection flaw), CVE-2025-10035 in Fortra GoAnywhere MFT, and CVE-2026-1731, a remote code execution vulnerability affecting BeyondTrust Remote Support. These aren't obscure products — ScreenConnect and BeyondTrust are common remote-support tools that many MSPs and IT teams run. If your provider hasn't patched them, attackers already have a roadmap.
Once they're inside, the group deploys several PowerShell stealth techniques with increasing complexity to obfuscate payloads, deletes PowerShell command line history to cover its tracks, and uses publicly available tools like Nezha for backdoor visibility and GSocket to bypass firewalls between private networks. Standard antivirus won't catch most of that.
What your managed-IT provider should be doing this week
This is a patch-and-monitor problem, not a mystery. Here's the checklist your IT team or MSP should already be running:
1. **Confirm patch status on remote-access tools.** ScreenConnect, BeyondTrust Remote Support, GoAnywhere MFT, and any Fortinet appliance need to be on current firmware — today, not next quarter. 2. **Turn on phishing-resistant MFA everywhere.** Medusa affiliates buy stolen credentials. MFA on email, VPN, remote desktop, and admin accounts turns a stolen password into a dead end. 3. **Monitor for PowerShell abuse.** Command-line history deletion, encoded PowerShell, and unusual scheduled tasks are the tells. That requires an EDR platform with actual humans watching it, not just an antivirus icon in the system tray. 4. **Test your backups by restoring from them.** Offline, immutable backups only help if they actually restore. Double-extortion means attackers steal data before encrypting it, so backups solve the outage but not the data-leak blackmail. 5. **Segment your network.** Flat networks are why a single compromised laptop becomes a company-wide encryption event.
If you're not sure whether any of this is happening on your network, that's the conversation to have with your provider this week. A layered defense — patching, MFA, EDR, backups, and monitoring — is exactly what York Computer's managed IT and cybersecurity services are built around. If you already have an internal IT person carrying the load, our co-managed IT support can add the 24/7 monitoring and after-hours coverage that catches Medusa-style intrusions before they reach the encryption stage.
What York Businesses Should Do
York County law firms, insurance offices, small manufacturers, and medical practices fit Medusa's target profile almost exactly. This week, ask your IT provider three specific questions: are our remote-access tools patched, is MFA enforced on every account, and when did we last successfully test a full restore from backup?
Sources
- Medusa ransomware gang has hit over 500 organizations, CISA warns
- CISA: Medusa ransomware hit over 500 critical infrastructure orgs
- #StopRansomware: Medusa Ransomware (Updated Aug. 18, 2026)
- Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware
- Medusa Ransomware Attacks 300+ Critical Infrastructure Organizations Using Double Extortion