Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

US Agencies Warn That Medusa Ransomware Now Operates Like a Subscription Service

The FBI, CISA and HHS issued an advisory that the Medusa ransomware-as-a-service group continues to threaten a wide range of sectors, especially healthcare, by renting its malware to affiliates.

Federal law-enforcement and health agencies released a joint advisory warning that the Medusa ransomware group has shifted to a ransomware-as-a-service model, leasing its tools to a growing network of cybercriminal affiliates. Since its identification over five years ago, Medusa has compromised more than 500 victims across critical infrastructure and commercial sectors, with a pronounced focus on healthcare and public-health organizations.

Attackers typically gain footholds by exploiting poorly secured Remote Desktop Protocol configurations, stolen administrative credentials, or unpatched software vulnerabilities, sometimes paying bounties from $100 up to $1 million for deployment assistance. The group uses a double-extortion approach, encrypting data while threatening to publish stolen information unless ransom demands are met. Analysts note that the service model lowers the technical barrier for attackers and accelerates the spread of ransomware, making rapid vulnerability remediation and robust backup strategies essential. Security professionals stress that resilient backups, network segmentation and tested response plans are critical to mitigate the heightened risk posed by this scalable threat.

Why it matters

The advisory shows how ransomware is becoming a subscription business, increasing the speed and scale of attacks on essential services.

In this story

ransomware-as-a-serviceMedusadouble extortionRDP vulnerabilitieshealthcare sectorcybercrime affiliatespatch managementincident responsebounty payments
Get the beta ↗