The FBI Just Refreshed Its Medusa Ransomware Warning for
Information Technology Solutions for Dentists and the Dental Industry. Serving the GTA and Southern Ontario.
Dental I/T, Dental Information Technology, Network Security, Toronto, GTA, Dental, Network, I/T, Information Technology, Computer, Data, Abeldent, Dentrix, LiveDDM, Patterson Dental, Henry Schein, K-Dental, Sinclair Dental, Schick CDR, Dexis, Carestream, Carestream Dental, Digital Radiography, X-ray, Dental X-ray, Dental Software Support, Software
18535
bp-nouveau,wp-singular,post-template-default,single,single-post,postid-18535,single-format-standard,wp-theme-bridge,wp-child-theme-bridge-child,theme-bridge,woocommerce-no-js,ajax_fade,page_not_loaded,,columns-4,qode-child-theme-ver-1.0.0,qode-theme-ver-10.0,wpb-js-composer js-comp-ver-4.12,vc_responsive

The FBI Just Refreshed Its Medusa Ransomware Warning for Healthcare: The Real Lesson for Your Dental Practice

A dental network diagram with two glowing entry doors at the edge - an email envelope and a remote-access appliance - and an intruder line slipping inside

The FBI Just Refreshed Its Medusa Ransomware Warning for Healthcare: The Real Lesson for Your Dental Practice

On August 18, 2026, three U.S. agencies – the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of Health and Human Services (HHS) – refreshed a joint advisory aimed squarely at the healthcare sector, warning about a ransomware operation called Medusa. The updated advisory ships fresh tactics, indicators of compromise, and remediation guidance, and the headline number is sobering: Medusa has now passed 500 victims across medical, education, legal, insurance, technology, and manufacturing organizations, with healthcare hit especially hard. A Canadian dental practice is not the marquee target of a federal U.S. advisory – but read how these attacks actually start and you will find your own network described in detail.

A dental network diagram with two glowing entry doors at the edge - an email envelope and a remote-access appliance - and an intruder line slipping inside
Medusa rarely breaks the front door down. It walks in through two familiar side doors: a phishing email, and an unpatched internet-facing appliance.

What Medusa actually is

Medusa is a ransomware-as-a-service (RaaS) operation, first identified in June 2021. Think of it less as a gang and more as a franchise. Since 2023 the core developers have run an affiliate model: they build and maintain the ransomware, and other criminals – affiliates – do the breaking-in, splitting the proceeds. That structure matters, because it means the people who compromise your network and the people who run the extortion are often not the same, and the whole thing scales like a business. It also runs on double extortion, which we will come back to.

The part that should worry a dental office: how they get in

Strip away the branding and Medusa gets in through two doors, and both of them are sitting on the average small-practice network right now.

The first is phishing – the same tired email that tricks a staff member into handing over a password or running an attachment. The second is unpatched software that faces the internet. Medusa’s affiliates recruit initial access brokers – criminals paid anywhere from $100 to $1 million to break in and resell that access – and the advisory names the products those brokers lean on: ScreenConnect, Fortinet, Fortra, and BeyondTrust. None of those are obscure. They are remote-support and remote-monitoring tools, firewalls, secure file transfer, and privileged-access software – precisely the categories a dental practice or its IT provider runs to keep the office online and supportable. The uncomfortable translation: the software that lets your IT company help you from across town is the same software a broker is hunting for a missing patch on.

An abstract illustration of an access broker handing a glowing key to a larger ransomware operator, with price-tag and transaction motifs
The affiliate model: brokers break in and sell the access; Medusa operators buy it and bring the ransomware. Breaking in is now a business.

And they move fast. The advisory notes brokers weaponize new vulnerabilities within 24 hours – sometimes before a flaw is even publicly announced. That is why a patching routine that runs “monthly, when we get to it” is not a routine at all for internet-facing gear. It is exactly the gap that lets a single overlooked box become the entry point, the same lesson behind why one patching policy cannot quietly cover every system you own.

Living off the land, then the squeeze

Once inside, Medusa’s operators do not announce themselves. They use legitimate remote-monitoring software – the very kind of tool a real IT provider uses – to blend in, move around, and quietly copy data out before anyone notices. Access brokers use the same trick to cover their tracks while they shop the access around. This is why simply owning security tools is not enough; you have to know what is supposed to be running on your network so that a rogue copy of a remote-access tool stands out instead of hiding in the noise. It is the same initial-foothold-then-quietly-expand pattern we saw with infostealers harvesting session cookies to slip past MFA.

Then comes the double extortion. Medusa encrypts your data so the practice cannot function – no charts, no schedule, no imaging – and it also threatens to publish the stolen files unless you pay. That second lever is the one that has changed the math for healthcare: even a practice with flawless backups, able to restore and reopen tomorrow, still faces the prospect of patient records posted on a leak site. We covered what that actually looks like when dental practices’ names appear on a ransomware blog. For a Canadian practice, that is not just downtime – it is a PHIPA privacy breach with reporting obligations attached.

A row of edge software panels with green update checkmarks, one cracked and glowing red to show a single unpatched product as the weak link
Attackers weaponize new flaws within 24 hours. One unpatched remote-access or firewall product is all the door they need.

Why you are in scope even though you were not named

It is easy to read “500 victims, mostly large organizations” and file it under someone else’s problem. That is the wrong read. An affiliate model with brokers paid to break in is, by design, indiscriminate about the victim’s size – it targets whatever is reachable and unpatched. A small dental office with a public-facing firewall that missed a firmware update, or a remote-support tool a year behind on patches, is not too small to be worth $100 of a broker’s time. It is exactly the opportunistic, automatable target that model was built to harvest. The named victims are big because big organizations get press; the broker’s scanner does not care what your letterhead says.

What a dental practice should do about it

The reassuring part of this advisory is that none of the defences are exotic. Make sure someone – your team or your IT provider – can confirm these five things:

  • Patch the edge, fast. Inventory every internet-facing device and service: firewall, VPN, remote-support tool, secure file transfer. Those get patched on a rapid cadence, not the general workstation schedule. If you run any of the named families (Fortinet, ScreenConnect, Fortra, BeyondTrust), confirm they are current today.
  • Make phishing fail. Move accounts to phishing-resistant MFA (passkeys or hardware keys) so a stolen password is not enough, and keep running staff phishing awareness. The advisory puts phishing tests and training at the top of its own mitigation list.
  • Know your own tools. Write down which remote-monitoring and remote-access tools legitimately run on your network, and alert on anything else. You cannot spot an attacker “living off the land” if you never mapped the land.
  • Keep offline, tested backups. Double extortion has not made backups useless – it has made them table stakes. Keep backups offline or immutable so ransomware cannot reach them, and actually test a restore. Backups answer the encryption; only prevention answers the data theft.
  • Use the advisory. The CISA/FBI/HHS advisory (AA25-071A) publishes concrete indicators of compromise and remediation steps. Have whoever manages your security review and block them – and if this rings any alarm bells about your current controls, revisit whether your cyber-insurance policy’s required security controls are genuinely in place, because an unmet requirement can void a claim exactly when you need it.
A split illustration showing patient files locked behind a padlock on one side and the same files held over a public board on the other
Double extortion: the data is encrypted so you cannot work, and copied so it can be published if you refuse to pay. Backups alone no longer end the story.

The through-line of the Medusa advisory is not a scary piece of malware; it is a supply chain of ordinary failures – an unpatched appliance, a reused password, an unmonitored remote tool – that criminals have industrialized into a repeatable break-in. Every one of those failures is fixable, and none of them require you to become a security expert. They require someone to own the list and work it.

A practice manager and IT professional reviewing an orderly security hardening checklist with green status indicators on a monitor
None of the defences are exotic: patch the edge fast, make phishing fail, know your own tools, and keep offline backups.

If you are not certain which of your internet-facing devices are fully patched, whether your remote-support tools are current, or whether your backups would actually survive a ransomware event, contact Compudent Systems. We help dental practices across Ontario inventory and harden the exact systems Medusa’s brokers hunt for – firewalls, remote-access tools, and edge software – lock down access with phishing-resistant MFA, and build tested, offline backups, so the way this ransomware gets in is closed before anyone comes knocking.


Sources & further reading:

Related Reading



Contact us today - How can we help you?