Skip to main content

August 24, 2026

Medusa Ransomware Is Buying Its Way Into Small Businesses

The FBI now counts more than 500 Medusa ransomware victims. What the updated advisory says, and the five checks small businesses should run first.

The tally went from 300 to 500

Last week the FBI, CISA, and the Department of Health and Human Services updated their joint advisory on Medusa ransomware. The March 2025 version counted more than 300 victim organizations. The update, reflecting FBI investigations through April 2026, puts the count past 500.

Read the sector list before assuming this is somebody else’s problem: medical, education, legal, insurance, technology, manufacturing, and financial services. That’s not a roster of Fortune 500 names. That’s the mid-market, the same mix of businesses you’d find in any Florida office park.

Medusa doesn’t break in. It buys in.

Medusa runs as ransomware-as-a-service, and its affiliates rarely do their own burglary. They recruit initial access brokers on criminal forums and pay between $100 and $1 million for a working way into a network. Think about the low end of that range. Somebody’s VPN credential or unpatched remote-access server is changing hands for the price of a dinner out.

Once inside, the clock starts. Victims get 48 hours to respond before the operators begin reaching out directly. And in a detail that says everything about how industrialized this has become, $10,000 in cryptocurrency buys one extra day on the leak-site countdown.

Stuck on something like this right now?

Talk it through with a real US-based engineer, 24/7, no phone trees: (407) 587-0089.

Book a Free Strategy Session

The break-in kit looks like an IT toolkit

Here’s the part that should get your attention if you outsource IT, or run it lean in-house. The advisory’s tool list reads like a managed service provider’s software stack: AnyDesk, Atera, ConnectWise, SimpleHelp, Splashtop, PDQ Deploy. Medusa affiliates favor legitimate remote access software because it blends in. An endpoint agent that flags malware won’t blink at a signed copy of AnyDesk.

On the exploit side, the group has targeted known holes in ScreenConnect (CVE-2024-1709) and Fortinet EMS (CVE-2023-48788), and reporting on the update adds recent Fortra GoAnywhere and BeyondTrust flaws to the list. The advisory notes the actors move on newly published exploits within 24 hours of disclosure. Patch windows measured in weeks don’t survive contact with that.

Post-compromise, it’s the familiar quiet playbook: PowerShell for stealth, Mimikatz for credentials, then exfiltration before encryption.

This is the second time this month we’ve written about attackers coming through the software IT providers themselves rely on. The N-able N-central exploitation taught the same lesson from a different angle: the tools that manage your network are part of your attack surface.

Where a 30-person company actually stands

You don’t need to be interesting to end up on a leak site. You need to be reachable. Access brokers scan wholesale, and a small manufacturer in Sanford with an unpatched firewall looks identical, from the internet, to any other unpatched firewall on earth.

The economics run against small businesses in a specific way. A company with 30 employees usually has nobody whose job is noticing that a new remote-access tool appeared on a workstation on Tuesday night. Detection is the whole game with Medusa, because by the time encryption starts, the data already left.

The advisory’s checklist, translated

The agencies’ recommendations are worth reading in full, but they compress to five moves. Turn on MFA everywhere that matters, starting with email, VPNs, and anything remote-facing. Patch internet-facing systems on a schedule measured in days, with remote access and file transfer software at the front of the line. Segment the network so one stolen credential can’t roam. Keep backups offline where an intruder with admin rights can’t reach them. And watch for legitimate tools showing up where they don’t belong.

That last one is the hard one, and it’s the honest case for managed security services: someone has to actually be looking at the telemetry, at 2 a.m., when a new AnyDesk install shows up on the CFO’s machine. Software alone doesn’t make that judgment call. This is what managed detection and response means in practice, a human noticing the thing that’s technically allowed but contextually wrong. Whether you run IT in-house or through a service provider, that monitoring gap is the one to close first.

One question for your current provider

Ask this today: which remote access tools are installed on our network, and when was each one last patched?

A provider on top of its stack answers from inventory, same day. If the answer takes a week, or the honest answer is that nobody knows, you’ve learned something important about your exposure, because Medusa’s affiliates are betting on exactly that fog. It’s also fair to ask what your provider is doing about its own tooling, since ScreenConnect and N-able sit on the provider side of the relationship. If the answers never quite arrive, it may be time to read up on what switching IT providers actually involves. The process is less painful than living with a vendor who can’t see their own attack surface.

Cyber Command runs a human-managed SOC out of Winter Springs, built to catch the quiet stuff, with real people answering 24/7 for businesses across Orlando, Tampa Bay, and Jacksonville, and across sectors from manufacturing to financial services. If the advisory has you wondering what’s actually installed on your network, call (407) 587-0089 or get in touch and we’ll help you find out.

#CyberSecurity #Ransomware #ManagedIT #SmallBusiness

This article is for general informational purposes only and is not legal, compliance, insurance, or other professional advice. Threats, technologies, and regulations change quickly; confirm current requirements with your own advisors before acting. See our full disclaimer.