you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 18 min ago 255 onions tracked
home / news / market watch
24 August 2026 market watch 4 min read

Medusa ransomware surge: 200-plus victims in a year and the mechanics of the onion leak site

Medusa has been quietly outpacing almost every other ransomware crew this year. On August 18, 2026, CISA, the FBI and the Department of Health and Human Services updated their joint advisory on the group, confirming that as of April 2026 Medusa actors had impacted more than 500 victims across critical infrastructure sectors. That is roughly 200 new victims in a single year, against about 300 total in the four years before. Demands have ranged from $100,000 to $15 million depending on the size of the organization, and investigators describe affiliates relying on legitimate remote monitoring tools such as AnyDesk, ConnectWise and SimpleHelp to blend into ordinary administrative traffic.

What the updated advisory says

The advisory, first issued in March 2025 as AA25-071A, draws on FBI investigations current through April 2026. Healthcare remains a primary target, alongside defense industrial base firms, manufacturers, government services, IT providers and financial services; victims outside critical infrastructure include education, insurance and law firms. The Record's coverage notes the group drew particular attention in April when it shut down the University of Mississippi Medical Center, the state's only children's hospital and Level I trauma center. Medusa began in June 2021 as a closed operation, then moved to a ransomware-as-a-service affiliate model in early 2023, around the time it launched its data leak site. Its developers recruit initial access brokers on criminal forums, offering anywhere from $100 to $1 million for network access, with better rates for brokers willing to work exclusively for the group.

The Medusa Blog and its countdown economy

The group's Tor-hosted shaming site, known as the Medusa Blog, runs the standard double-extortion playbook with unusually granular monetization. Each victim entry carries a price tag for deletion, a separate price at which third parties can download the stolen files, and a public countdown timer to release. Pressure extends beyond the page itself: ransom notes give victims 48 hours to make contact through a Tor-based live chat or the Tox encrypted messenger, silence triggers direct approaches by phone and email, demands are calibrated against publicly reported company revenue, and posts list claimed view counts alongside affiliate cryptocurrency wallet addresses. As Palo Alto Networks Unit 42 documented when the site appeared in early 2023 (Unit 42), every option carries a number attached:
  • A flat $10,000 in cryptocurrency buys the victim exactly one extra day before publication.
  • Data is concurrently advertised for sale to interested buyers while the timer runs.
  • A “lower rate” is offered for quick payment, with an arbitrary expiry attached.
  • After payment, the entry supposedly disappears, though the agencies state there is no way to verify actual deletion.

Speed, layered extortion and the 2026 landscape

Two operational habits explain much of the surge. First, velocity at exploitation: Microsoft's April 2026 research into the Storm-1175 activity cluster found Medusa actors weaponizing newly disclosed vulnerabilities within 24 hours, sometimes using exploits up to a week before public disclosure (Microsoft Security Blog). Second, layered extortion. In one FBI-investigated case, after a victim paid, a separate Medusa actor demanded half the ransom again for the “true decryptor”, claiming the original negotiator had stolen the funds.
“Potentially indicating a triple-extortion scheme, or operational dysfunction and a lack of cohesion among ransomware group.”
Medusa sits inside a crowded field: tracking projects such as ransomware.live log dozens of new leak sites stood up by emerging brands through the first half of 2026, even as established names collapse or rebrand. Notably, The Record reports that Medusa itself has added no new victims to its leak site since April, with several observers speculating that the Mississippi hospital attack attracted unwanted law enforcement attention. Whether that is a pause, a rebrand or simply a slow cycle for affiliates remains an open question. For defenders and researchers, the practical lesson is unchanged from our earlier look at ransomware leak sites on Tor: uptime and posting cadence on these onions are signals, and watching them costs little. A leak site that goes quiet after a high-profile hospital attack tells you something, though what exactly takes months to confirm. Most Medusa intrusions still start with phishing or an unpatched internet-facing device rather than anything exotic, which makes patching internet-facing systems, segmenting networks and filtering remote access traffic the same unglamorous advice worth repeating despite its familiarity.

more notes

all news ›