The U.S. government advisory reports that Medusa ransomware has gained hundreds of victims, increasing from over 300 to more than 500 since March 2025. The group employs access brokers, paying between $100 and $1 million, and targets unpatched software vulnerabilities, notably in Fortra GoAnywhere and BeyondTrust. Medusa actors utilize legitimate tools for evasion and exploit newly announced vulnerabilities rapidly. The healthcare sector remains a frequent target, with operations noted since 2021.











































