Medusa Ransomware Targets Healthcare: What SMBs Should Know


Security researchers reported earlier this year that operators linked to North Korea’s Lazarus Group have started using Medusa ransomware in attacks against U.S. healthcare and nonprofit organizations. If that sentence sounds like it belongs in a spy thriller rather than a conversation about your business’s IT budget, we understand — but the underlying lesson applies directly to small and mid-sized organizations, especially in healthcare, education, legal, and manufacturing.

What Happened

Medusa is a ransomware-as-a-service operation that’s been active since 2021 and has been linked to attacks against hundreds of organizations in critical infrastructure sectors. Researchers found that a state-linked group historically known for espionage and cryptocurrency theft has now adopted Medusa as a tool for extortion attacks, with confirmed targeting of a U.S. healthcare organization and a Middle East entity. Several of the healthcare and nonprofit victims tied to this activity were smaller organizations — not hospital systems with dedicated security teams, but the kind of regional and community-level providers many of our clients resemble.

What “Double Extortion” Actually Means

Older ransomware attacks were simple: your files get encrypted, you pay to get them back. Double extortion adds a second layer of pressure. Before the encryption even happens, attackers quietly copy your sensitive data out of your systems. Then they threaten two things at once — you won’t get your files back, and your stolen data will be published or sold if you don’t pay. For a healthcare practice, that second threat is often the more damaging one, since it can mean patient records, billing details, or protected health information ending up exposed regardless of whether a ransom is paid.


Why Healthcare Keeps Showing Up on These Lists

It isn’t bad luck. Healthcare and adjacent organizations hold data that’s valuable to attackers and operationally can’t afford extended downtime, which makes them more likely to consider paying. Add in the reality that many smaller healthcare practices run lean IT teams focused on keeping systems running day to day, with no one specifically responsible for anticipating attacks like this one — and the sector becomes a consistent, attractive target regardless of company size.

Where This Actually Gets Stopped

None of this means a small practice needs an enterprise security budget. It means someone needs to own three things before an incident happens, not during one: a documented incident response plan that spells out who does what in the first hours of a suspected breach, regular backup testing so “restore from backup” is actually a real option rather than a hopeful assumption, and an honest risk assessment that identifies where your organization’s exposure actually sits today.

This is exactly the kind of planning a vCISO builds before there’s ever a crisis to respond to. Incident response plans that are written, tested, and understood by staff turn a potential catastrophe into a contained, manageable event — the difference often comes down to whether the plan existed on paper before day one of the attack.

What to Do Right Now

If your organization doesn’t currently have a written incident response plan, start there. If you have one but haven’t reviewed it in the past year, that’s worth revisiting too — threat actors and their tactics change quickly, and a plan written two years ago may not reflect how attacks actually unfold today. Our ransomware protection guide for SMBs covers foundational defenses if you’re starting from scratch.

Frequently Asked Questions

What is double extortion ransomware? Double extortion is a ransomware technique where attackers steal sensitive data before encrypting a victim’s systems, then threaten to both withhold the decryption key and publicly release the stolen data unless a ransom is paid.

Is Medusa ransomware still active in 2026? Yes. Medusa remains an active ransomware-as-a-service operation, and security researchers have documented continued attacks throughout 2026, including new activity linked to North Korea’s Lazarus Group targeting healthcare organizations.

How can a small healthcare practice protect against ransomware? Core protections include a written and tested incident response plan, regularly tested backups stored separately from your main network, multi-factor authentication on all critical systems, and an ongoing risk assessment process to catch new exposures before attackers do.

Do small practices really get targeted, or just large hospital systems? Smaller organizations are targeted regularly. Attackers often view smaller healthcare practices and nonprofits as easier targets precisely because they’re less likely to have dedicated security staff or a tested response plan in place.

If you’d like an honest look at where your incident response readiness currently stands, that’s exactly the kind of assessment our vCISO team starts with — no pressure, just clarity on where you stand.