The Medusa ransomware-as-a-service group has significantly expanded its victim count over the past year and refined how it buys its way into target networks, according to an updated U.S. government advisory released Tuesday. The advisory, which revises earlier guidance on the group's methods, is a direct signal to healthcare organizations — a sector Medusa has targeted repeatedly — that the threat is growing in both scale and sophistication.

How Medusa is buying its way in

The updated advisory describes Medusa's increased reliance on access brokers: third-party operators who sell footholds inside victim networks to ransomware affiliates. According to the advisory, Medusa compensates those brokers anywhere from $100 to $1 million, with higher payments going to brokers who can deliver access to more valuable targets.

This model separates the work of initial compromise from the work of deploying ransomware and conducting extortion. For healthcare organizations, that distinction matters operationally — a network may already be silently accessed before any ransomware activity is detectable, shrinking the window for intervention.

What the victim count signals

Hundreds of new victims in a little more than a year represents a meaningful escalation in operational tempo. Ransomware-as-a-service groups that pay for access rather than conducting their own phishing or exploitation campaigns can scale faster than groups that handle the full attack chain internally, because the barrier to each new intrusion is lowered to a financial transaction rather than a technical operation.

Healthcare entities — including independent practices, specialty clinics, and regional health systems — remain attractive targets given the sensitivity of protected health information and the operational pressure to restore systems quickly. That pressure historically increases the probability that a ransom demand will be met, which in turn sustains the economics of the access-broker model.

Where independent practices are most exposed

What this means for compliance planning

The advisory's publication by U.S. federal agencies gives compliance officers a documented, current government source to reference when presenting risk assessments to leadership or boards. Threat intelligence drawn from official advisories carries weight in demonstrating that a recognized, active adversary is targeting organizations of a given type and size — which is relevant both to risk analysis requirements under the HIPAA Security Rule and to any cyber-insurance underwriting conversations.

Practices should review whether their incident response plans account for the access-broker scenario specifically: an intrusion that predates any ransomware indicator and that may involve valid credentials rather than malware signatures. Tabletop exercises that begin the scenario at the point of ransomware detonation will miss the earlier, quieter phase that the advisory now describes in greater detail.