August 31, 2026 The FBI Just Refreshed Its Medusa Ransomware Warning for Healthcare: The Real Lesson for Your Dental Practice
On August 18, 2026, three U.S. agencies – the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of Health and Human Services (HHS) – refreshed a joint advisory aimed squarely at the healthcare sector, warning about a ransomware operation called Medusa. The updated advisory ships fresh tactics, indicators of compromise, and remediation guidance, and the headline number is sobering: Medusa has now passed 500 victims across medical, education, legal, insurance, technology, and manufacturing organizations, with healthcare hit especially hard. A Canadian dental practice is not the marquee target of a federal U.S. advisory – but read how these attacks actually start and you will find your own network described in detail.

What Medusa actually is
Medusa is a ransomware-as-a-service (RaaS) operation, first identified in June 2021. Think of it less as a gang and more as a franchise. Since 2023 the core developers have run an affiliate model: they build and maintain the ransomware, and other criminals – affiliates – do the breaking-in, splitting the proceeds. That structure matters, because it means the people who compromise your network and the people who run the extortion are often not the same, and the whole thing scales like a business. It also runs on double extortion, which we will come back to.
The part that should worry a dental office: how they get in
Strip away the branding and Medusa gets in through two doors, and both of them are sitting on the average small-practice network right now.
The first is phishing – the same tired email that tricks a staff member into handing over a password or running an attachment. The second is unpatched software that faces the internet. Medusa’s affiliates recruit initial access brokers – criminals paid anywhere from $100 to $1 million to break in and resell that access – and the advisory names the products those brokers lean on: ScreenConnect, Fortinet, Fortra, and BeyondTrust. None of those are obscure. They are remote-support and remote-monitoring tools, firewalls, secure file transfer, and privileged-access software – precisely the categories a dental practice or its IT provider runs to keep the office online and supportable. The uncomfortable translation: the software that lets your IT company help you from across town is the same software a broker is hunting for a missing patch on.

And they move fast. The advisory notes brokers weaponize new vulnerabilities within 24 hours – sometimes before a flaw is even publicly announced. That is why a patching routine that runs “monthly, when we get to it” is not a routine at all for internet-facing gear. It is exactly the gap that lets a single overlooked box become the entry point, the same lesson behind why one patching policy cannot quietly cover every system you own.
Living off the land, then the squeeze
Once inside, Medusa’s operators do not announce themselves. They use legitimate remote-monitoring software – the very kind of tool a real IT provider uses – to blend in, move around, and quietly copy data out before anyone notices. Access brokers use the same trick to cover their tracks while they shop the access around. This is why simply owning security tools is not enough; you have to know what is supposed to be running on your network so that a rogue copy of a remote-access tool stands out instead of hiding in the noise. It is the same initial-foothold-then-quietly-expand pattern we saw with infostealers harvesting session cookies to slip past MFA.
Then comes the double extortion. Medusa encrypts your data so the practice cannot function – no charts, no schedule, no imaging – and it also threatens to publish the stolen files unless you pay. That second lever is the one that has changed the math for healthcare: even a practice with flawless backups, able to restore and reopen tomorrow, still faces the prospect of patient records posted on a leak site. We covered what that actually looks like when dental practices’ names appear on a ransomware blog. For a Canadian practice, that is not just downtime – it is a PHIPA privacy breach with reporting obligations attached.

Why you are in scope even though you were not named
It is easy to read “500 victims, mostly large organizations” and file it under someone else’s problem. That is the wrong read. An affiliate model with brokers paid to break in is, by design, indiscriminate about the victim’s size – it targets whatever is reachable and unpatched. A small dental office with a public-facing firewall that missed a firmware update, or a remote-support tool a year behind on patches, is not too small to be worth $100 of a broker’s time. It is exactly the opportunistic, automatable target that model was built to harvest. The named victims are big because big organizations get press; the broker’s scanner does not care what your letterhead says.
What a dental practice should do about it
The reassuring part of this advisory is that none of the defences are exotic. Make sure someone – your team or your IT provider – can confirm these five things:
- Patch the edge, fast. Inventory every internet-facing device and service: firewall, VPN, remote-support tool, secure file transfer. Those get patched on a rapid cadence, not the general workstation schedule. If you run any of the named families (Fortinet, ScreenConnect, Fortra, BeyondTrust), confirm they are current today.
- Make phishing fail. Move accounts to phishing-resistant MFA (passkeys or hardware keys) so a stolen password is not enough, and keep running staff phishing awareness. The advisory puts phishing tests and training at the top of its own mitigation list.
- Know your own tools. Write down which remote-monitoring and remote-access tools legitimately run on your network, and alert on anything else. You cannot spot an attacker “living off the land” if you never mapped the land.
- Keep offline, tested backups. Double extortion has not made backups useless – it has made them table stakes. Keep backups offline or immutable so ransomware cannot reach them, and actually test a restore. Backups answer the encryption; only prevention answers the data theft.
- Use the advisory. The CISA/FBI/HHS advisory (AA25-071A) publishes concrete indicators of compromise and remediation steps. Have whoever manages your security review and block them – and if this rings any alarm bells about your current controls, revisit whether your cyber-insurance policy’s required security controls are genuinely in place, because an unmet requirement can void a claim exactly when you need it.

The through-line of the Medusa advisory is not a scary piece of malware; it is a supply chain of ordinary failures – an unpatched appliance, a reused password, an unmonitored remote tool – that criminals have industrialized into a repeatable break-in. Every one of those failures is fixable, and none of them require you to become a security expert. They require someone to own the list and work it.

If you are not certain which of your internet-facing devices are fully patched, whether your remote-support tools are current, or whether your backups would actually survive a ransomware event, contact Compudent Systems. We help dental practices across Ontario inventory and harden the exact systems Medusa’s brokers hunt for – firewalls, remote-access tools, and edge software – lock down access with phishing-resistant MFA, and build tested, offline backups, so the way this ransomware gets in is closed before anyone comes knocking.
Sources & further reading:
- Medusa Ransomware Hitting Healthcare Industry’s Unpatched Software Vulnerabilities – National Law Review
- #StopRansomware: Medusa Ransomware (AA25-071A) – CISA
- SWK Cybersecurity News Recap August 2026
Related Reading
- Ransomware Is Now a Patient-Safety Issue: What a 38% Hospital Mortality Study Means for Your Dental Practice
- Two Dental Groups on Leak Sites in One Week: What It Means When Your Practice’s Name Appears on a Ransomware Blog
- Dental Practices Under Siege: The Rising Threat of Ransomware Targeting Healthcare Data