Medusa Pays Access Brokers Up to $1 Million and Has Now Passed 500 Victims. The New Advisory Names Healthcare Specifically.
- Patrick Duggan
- 1 day ago
- 5 min read
The FBI, CISA and HHS updated advisory AA25-071A on August 18 with FBI investigative findings current to April 2026. Two things in the update deserve more attention than they are getting.
Medusa has passed 500 victims across critical infrastructure — healthcare, education, legal, insurance, technology and manufacturing.
Medusa pays initial access brokers between $100 and $1,000,000, with the top of that range reserved for brokers who work exclusively with Medusa.
And the update adds specific targeting of the Healthcare and Public Health sector, which is why it carries HHS as a co-author this time.
What We Hold, Stated Plainly
We carry 208 indicator records attributed to this advisory in our feed. That includes the gaze.exe encryptor hash, the .medusa file extension, the ransom note filename, the Tor leak site, a C2 domain, and the svhost scheduled-task persistence artifact that re-executes every fifteen minutes.
Now the part where most vendors would tell you they were ahead of this. We were not, and here is the honest accounting.
Those 208 records carry the source tag cisa-aa25-071a. That is not a detection timestamp. It is an ingest timestamp — the date we pulled CISA's published work into our index. CISA found these. The FBI found these. We redistributed them.
Our own rule on this is blunt and we wrote it after getting it wrong in public: ingest time is not detection time. A record harvested by our own scanning and a record imported from a government PDF look structurally identical in the index, which makes "in our feed since March" technically true and completely misleading when March is when we downloaded somebody else's report. We published a correction post about exactly that failure in July, on a different campaign, and the rule exists because of it.
So the claim here is not a lead. The claim is distribution: if you are a small hospital system or a rural clinic without a CTI budget, these indicators are free, they are in ips.csv and domains.csv and hashes.csv right now, and you can point a MISP instance at our feed and have them in your stack this afternoon. That is worth something. It is just not worth pretending it is a scoop.
The one thing we did carry independently is the Storm-1175 campaign record from April 6, tracking the high-tempo Medusa operations Microsoft documented — the crew that weaponizes recently disclosed vulnerabilities against web-facing assets for initial access. That is corroboration we assembled, alongside the government indicators, not ahead of them.
The Access Broker Economics Are the Real Story
Everyone will lead with "500 victims." That is the wrong number. The interesting number is the price schedule.
$100 to $1,000,000, with a premium for exclusivity.
Sit with the shape of that range. It is four orders of magnitude, and it tells you the market has matured past anything resembling a hacking scene into something with genuine price discovery.
A $100 payout is a commodity credential — something that fell out of an infostealer log, one of ten thousand, worth roughly what a single lottery ticket is worth because most of them lead nowhere.
A $1,000,000 payout with an exclusivity clause is not a credential at all. That is domain administrator on a large, wealthy, insured organization, sold to one buyer so the victim does not get hit by three crews at once and lose its ability to pay. That is a negotiated commercial arrangement with a supplier who has other options.
The exclusivity premium is the detail that should worry defenders most, because it reveals competition on the buy side. Medusa is paying extra to keep brokers away from rivals, which means brokers have rivals bidding. The bottleneck in the ransomware economy is no longer encryption tooling, or affiliates, or infrastructure — those are all commoditized. The bottleneck is access, and it now has a market price.
That reframes defensive spending. Every control that makes initial access harder does not merely reduce your probability of compromise; it raises your price in a market where somebody is literally quoting one. Every control that fails silently — the MFA gap, the deprecated auth flow, the forgotten VPN appliance — is not just a hole, it is inventory somebody is being paid to find.
Why Healthcare, Explicitly
The update names Healthcare and Public Health targeting, and HHS co-signs it. The logic is grim and simple.
Healthcare is the sector where downtime converts to physical harm fastest, which maximizes payment pressure. It runs enormous quantities of legacy and medical equipment that cannot be patched on a normal cycle, or at all, because the device is FDA-cleared in a specific configuration. It has thin security budgets outside the large systems. And it holds data whose sensitivity gives leak-site extortion independent leverage even when backups are clean.
That last point is what makes double extortion so effective here specifically. A manufacturer with good backups can often tell a ransomware crew to pound sand and restore. A hospital with good backups still faces the publication of patient records, and there is no restoring from that.
We have been writing this sector all year — Omnicell and the Everest listing, the Abbott double-breach week, the iRhythm cardiac patient data, the medical device sector map where we scored our own hits and misses honestly. Medusa naming healthcare explicitly is the same thesis arriving through the ransomware-as-a-service door.
What Actually Helps
The advisory's mitigations are the standard set and they are correct. I will point at the three that map to what is actually in the update.
Close the access-broker supply chain. Since the initial access market is the bottleneck, this is where marginal effort pays best. Phishing-resistant MFA everywhere it will go, and — critically — audit for the places where MFA is configured but bypassable through a legacy or deprecated auth path. That gap is being actively farmed right now across the industry, and it is precisely the kind of finding a broker sells.
Patch the internet-facing edge on a campaign clock, not a quarterly one. Medusa has exploited Fortra GoAnywhere and BeyondTrust flaws, and the Storm-1175 pattern is weaponizing recently disclosed vulnerabilities against web-facing assets. The window between disclosure and mass exploitation on edge products is now measured in days.
Pull the indicators, they cost nothing. They are in our free feed. They are in plenty of other free feeds. Every organization mentioned in this advisory's victim range could have blocked the known infrastructure for the price of an afternoon's integration work. That does not stop a determined operator with fresh infrastructure, and I will not pretend it does — but it raises the floor, and the floor is where most of the 500 fell through.
The Part Nobody Says Out Loud
Five hundred victims is a business doing well. The advisory documents a functioning supply chain with suppliers, pricing tiers, exclusivity contracts and sector specialization. That is not a gang. That is an industry with a procurement function.
We are not going to indicator-block our way out of a market. What we can do is make the raw material expensive, and the raw material is initial access to your organization specifically. Somebody is being offered up to a million dollars to find the way in. The honest question for any defender reading this is not whether your controls are good. It is what your organization is currently worth on that price list, and which specific gap sets it.
Sources
FBI, CISA and HHS — AA25-071A, "#StopRansomware: Medusa Ransomware," updated August 18, 2026, with FBI investigative findings current to April 2026, at cisa.gov/news-events/cybersecurity-advisories/aa25-071a
CyberScoop, "Medusa ransomware tallies hundreds of new victims, says updated advisory on group's tactics," August 18, 2026
Microsoft Security Blog analysis of Storm-1175, April 6, 2026
Our 208 attributed indicator records are in the free feed at analytics.dugganusa.com/api/v1/stix-feed — CSV blocklists and a MISP feed endpoint, free key, no cost.
If you pulled these into a stack and they did or did not fire, that is exactly the feedback we cannot get any other way. Rate this post below — one click.
Her name was Renee Nicole Good.
His name was Alex Jeffery Pretti.




Comments