FBI says Medusa tops 500 healthcare victims
A joint FBI, CISA and HHS notice says Medusa has hit more than 500 victims since 2021, with healthcare a frequent target.
A joint FBI, CISA and HHS notice updated in August said Medusa has compromised more than 500 critical infrastructure organizations since 2021, with Healthcare and Public Health as a frequent target. At the same time, leak monitoring linked new claims by CoinbaseCartel to Integrated Health Systems and by STORM to Pinnacle Hospital, both in the United States, although official confirmation is still lacking in those two cases.
A joint FBI, CISA and HHS notice updated in August said Medusa has compromised more than 500 critical infrastructure organizations since 2021, with Healthcare and Public Health among its frequent targets. At the same time, leak monitoring attributed new claims by [CoinbaseCartel](https://medrisk.io/2026/08/23/coinbase-cartel-lists-medical-billing-firm-integrated-health-systems/) against [Integrated Health Systems](https://www.ransomware.live/id/SW50ZWdyYXRlZCBIZWFsdGggU3lzdGVtc0Bjb2luYmFzZWNhcnRlbA) and by STORM against Pinnacle Hospital, both in the United States, although official confirmation is still missing in both cases.
What did the notice say about Medusa?
The joint document, updated on August 18 and 19, 2026, says Medusa operates as ransomware-as-a-service and uses a double-extortion model, stealing data and threatening to leak it on a Tor site. According to the notice, the group has surpassed 500 compromised organizations since 2021, and the healthcare sector is among its recurring targets.
SWK Cybersecurity News Recap also reported that the notice, updated on August 18, said there were more than 500 victims through April 2026, including healthcare organizations. That reference reinforces that pressure on hospitals and health systems is not limited to isolated cases, but appears as a sustained pattern within the campaign attributed to Medusa.
What happened with Integrated Health Systems?
Malware.news said CoinbaseCartel claimed a ransomware attack against Integrated Health Systems, a U.S. healthcare organization, and threatened to publish sensitive data if the company did not get in touch. The report, however, said that claim had not been independently confirmed.
Ransomware.live logged the Integrated Health Systems entry under the domain ihs911.com, with discovery at 14:01 UTC on August 22, 2026, and an estimated attack date also set for that day. HackerFeeds, meanwhile, listed the organization as a CoinbaseCartel target, classified the sector as healthcare, and recorded August 22, 2026, as both the breach and discovery date.
MedRisk added that CoinbaseCartel placed it within an ongoing campaign against the medical billing firm, alleging internal data without specifying the volume or type of files. The same coverage said trackers such as Ransomware.live, GalaxyWarden and RansomLook all matched the entry to August 22, but the claim still lacks public verification from the provider.
What is known about STORM and Pinnacle Hospital?
Security Arsenal reported seven new victim posts on STORM's leak site between August 21 and 23, 2026, including Pinnacle Hospital in the United States. The firm interpreted that series as a possible sign of a coordinated wave of intrusions or a batch release of earlier compromises.
MedRisk said STORM posted Pinnacle Hospital, an acute care hospital owned by physicians in Crown Point, Indiana, on its leak site on August 23, 2026, with Ransomware.live estimating the intrusion date as August 21. Security Arsenal also placed it in the healthcare sector and listed 2026-08-21 as the publication date within the same batch of seven entries.
In both cases, attribution still depends on dark web monitoring rather than official confirmation from the hospital or its operator.
Sources
- CoinbaseCartel Breaches Integrated Health Systemsmalware.news· Malware.news
- Ransomware group coinbasecartel hits Integrated Health Systemshackerfeeds.com· HackerFeeds
- STORM Ransomware Gang: 7 New Victims Posted in 72 Hourssecurityarsenal.com· Security Arsenal
- Storm gang claims Indiana acute care hospital in fresh leak postmedrisk.io· MedRisk
- SWK Cybersecurity News Recap August 2026swktech.com· SWK Technology
- Coinbase Cartel lists medical billing firm Integrated Health Systemsmedrisk.io· MedRisk
- Federal advisory warns of Gunra ransomware targeting healthcarepaubox.com· Paubox
- Protect Against Medusa Ransomware Attacksampcuscyber.com· Ampcus Cyber
- Weekly Threat Intelligence Report: DGFiP, Azure, Medusafirecompass.com· FireCompass
- CISA: Medusa ransomware hit over 500 critical infrastructure orgsisecurify.co· iSecurify
- Ransomware Medusa atinge mais de 500 organizações críticasinfoalfasa.com.br· Infoalfasa
- Medusa Tops 500 Victims: CISA Updates Advisory on 24-Hour Exploit Windowdeafnews.it· DeafNews
- Victim: Integrated Health Systemsransomware.live· Ransomware.live



