Three Agencies Rewrote the Medusa Advisory. Tribal Governments Are Named in It.
The FBI, CISA and HHS updated their Medusa ransomware advisory on August 18. Over 500 victims, and the intended audience line names Tribal governments directly.
On August 18, the FBI, CISA and the Department of Health and Human Services published an updated version of their joint advisory on Medusa ransomware. The advisory carries product ID AA25-071A and was originally issued in March 2025. This update folds in what the FBI learned from investigations through April 2026.
Most tribal IT staff will never see it. It is a twenty-nine page technical document written for network defenders, full of MITRE ATT&CK mappings and PowerShell command syntax. The part worth your attention is on page two, and it is not technical at all.
The audience line
Every joint advisory carries a field called Intended Audience. On this one it reads: Government, Federal Civilian Executive Branch, State, Local, Tribal, and Territorial (SLTT) Governments, and Critical Infrastructure.
Tribal governments are named. Not implied, not covered by a general reference to public sector entities. Named.
Then, one line down, the advisory lists the sectors: Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. And in the introduction, the industries actually hit: medical, education, legal, insurance, technology, and manufacturing.
Read those two lists next to each other and the shape of the problem for a tribe becomes clear. HHS was added to this advisory as a co-sealer specifically to contribute what it knows about Medusa operations against the Healthcare and Public Health sector. That is a separate agency joining a document because the health sector is getting hit hard enough to warrant it.
A tribal government with a 638 clinic is in the healthcare sector. The same government runs a school or a tribal college, which is education. It runs a court, which is legal. It may run a utility, a housing authority, a casino, and a police department. Federal guidance treats each of those as a distinct sector with its own threat picture and its own defenders.
In a tribe, they are frequently one network, one domain, one backup system, and one IT department that might be three people.
That is the condition this advisory does not account for, and it is the condition we see most often in Indian Country. The federal frameworks assume a hospital has a hospital's security team and a court has a court's. A tribal government inherits the combined attack surface of six sectors and a single budget line to defend it.
What the update actually changed
The revision is not cosmetic. As of April 2026, Medusa actors have impacted over 500 victims across critical infrastructure sectors. The authoring agencies expanded the advisory to describe the group's affiliate structure, a broader list of exploited vulnerabilities, its opportunistic targeting, and a longer inventory of tools used for network enumeration, persistence, and stealth.
The detail we keep coming back to is about how these actors get in. Medusa operators recruit initial access brokers on criminal forums and marketplaces, and the advisory says they offer payments ranging from $100 to $1 million for that access. Most of those brokers, per the FBI, are willing to sell to multiple ransomware operations rather than work exclusively for one.
That number has a wide floor for a reason. Access to some organizations is worth a hundred dollars. It is bought and sold as a commodity by people who never run the ransomware themselves, and the group encrypting your files is often not the group that found the way in.
Medusa runs a double extortion model. Data is encrypted, and exfiltrated copies are held over the victim with a threat of public release. For a tribal health program, the second half of that is the one that matters. Restoring from backup solves the encryption. It does nothing about patient records sitting on a leak site.
The three actions the agencies put first
The advisory lists a long set of mitigations. The authoring agencies elevated three of them into the summary, which is a useful signal about where to start.
Patch known exploited vulnerabilities on internet-facing systems. The advisory calls timely patching one of the most efficient and cost-effective steps available, and asks organizations to prioritize internet-facing systems specifically. That is the front door the access brokers are selling.
Segment the network. This is the one that speaks directly to the tribal structure problem above. If the clinic, the court, the casino and the housing authority share a flat network, then access purchased for a hundred dollars against the weakest of them reaches all of them. Segmentation is what turns a government-wide incident into a department-wide one.
Filter traffic from unknown or untrusted origins reaching remote services. The purpose is specific: it stops actors from connecting directly to the remote access services they set up for persistence after they are already inside.
Below those, the full mitigations list includes items worth reading against your own environment. Phishing-resistant multifactor authentication, called out for webmail, VPNs, and accounts that reach critical systems. Backups that are offline, encrypted, and immutable, meaning they cannot be altered or deleted, and that cover the whole organization rather than the systems someone remembered to include. An audit of accounts holding administrative privilege. A review of domain controllers and Active Directory for accounts nobody recognizes.
There is also a quiet correction in there for anyone still running an old password policy. The advisory asks for long passwords and says to consider not requiring frequent recurring changes, because forced rotation weakens security. If your tribal IT policy still mandates a password change every sixty days, federal guidance no longer agrees with you.
Where we would start
Not with the twenty-nine pages. With a map.
Write down every distinct function your government operates, and next to each one write whether it sits on a shared network with the others. Health, education, courts, enterprise, public safety, administration. That single page tells you more about your actual exposure than any vulnerability scan, because it tells you what one purchased credential reaches.
Then check the three summary items against that map, starting with whatever is internet-facing. Most tribal governments we work with are not lacking a security product. They are carrying an architecture that grew one department at a time, and nobody has ever drawn the whole thing on one sheet of paper.
The advisory is free, public, and marked TLP:CLEAR, which means you can distribute it without restriction. Send it to your IT staff and to whoever runs your health program. They are both in the audience line.
If you want help reading your own environment against it, that is a conversation we are glad to have.
Join the conversation
Straight talk welcome. Comments are moderated, no pitches, no spam.
Comments load once the Hyvor Talk Website ID is set in
article.html.