Medusa tops 500 victims in health sector
FBI, CISA and HHS updated their Medusa alert, saying the group has hit more than 500 victims and kept targeting US health care.
FBI, CISA and HHS updated their joint warning on Medusa and said the group has affected more than 500 victims since 2021, including health organizations in the United States. The guidance adds two new vulnerabilities tied to the campaign and comes as hospitals in Missouri and other health care centers report recent incidents involving possible data exposure.
The FBI, CISA and HHS updated their joint advisory on Medusa, saying the group has affected more than 500 victims since 2021, including health organizations in the United States. The warning also adds two new vulnerabilities linked to the group's activity and arrives as hospitals in Missouri and other health care centers report recent incidents.
What did the new Medusa alert say?
The joint update says Medusa was used against US hospitals and health systems over the past few years and that, as of April 2026, the group had impacted more than 500 victims across multiple critical infrastructure sectors, including public health.
According to the updated notice, the FBI investigated the cases that informed the guidance through April 2026, and HHS is now listed as a coauthor. Becker's Hospital Review reported that the new total is higher than the more than 300 victims confirmed in the original advisory.
What vulnerabilities did the alert add?
The document added two more flaws tied to Medusa activity, according to Tech Informed. They are CVE-2025-10035, which affects Fortra GoAnywhere MFT, and CVE-2026-1731, tied to BeyondTrust Remote Support and Privileged Remote Access.
| CVE | Affected product | Source |
|---|---|---|
| CVE-2025-10035 | Fortra GoAnywhere MFT | Tech Informed |
| CVE-2026-1731 | BeyondTrust Remote Support and Privileged Remote Access | Tech Informed |
What happened in the hospitals mentioned?
Cameron Regional Medical Center said it discovered a ransomware attack on June 18, 2026, and that the investigation was still ongoing as of August 17. The hospital warned patients that protected health information may have been exposed, and said it did not yet know of any fraudulent use of that data.
In parallel, the reviewed material on that case says the Anubis group claimed responsibility on August 3, 2026, and threatened to publish stolen data, although the hospital had not publicly confirmed that attribution in the available documentation.
What level of impact is attributed to Medusa?
The update released by the agencies says Medusa was responsible for a high-impact attack on a Level 1 trauma center in 2026, disrupting care. The American Hospital Association also said the group has been used against US hospitals and health systems for several years.
Why is it back in the health care spotlight?
Because the alert and the recent incidents focus on health care providers, a sector that has already been among those hit by the campaign. The new material published by CISA, FBI and HHS updates the group's scope while hospitals continue to report attacks with possible patient data exposure.
Sources
- Agencies issue update on Medusa ransomware activityaha.org· American Hospital Association
- HHS, FBI warn hospitals as Medusa ransomware tops 500 victimsbeckershospitalreview.com· Becker's Hospital ReviewUnverified URL
- New cybersecurity committee follows years of attacksmsindy.org· Mississippi State University Independent?
- Missouri hospital hit by ransomware attackbeckershospitalreview.com· Becker's Hospital ReviewUnverified URL
- CISA, FBI and HHS Update Joint Cybersecurity Advisory on Medusa Ransomwarecontent.govdelivery.com· CISA
- CISA flags healthcare as frequent Medusa ransomware victimtechinformed.com· Tech Informed
- Notice of Data Incidentaol.com· AOL
- Ransomware attacks surge in 2026 with bold new extortion tacticsque.com· QUE.com



