UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

Medusa Ransomware 2026: What UK CNI Buyers Must Do Now

London · Servnet News Desk · IT infrastructure analysis3 min read
Share

CISA, HHS and the FBI have confirmed that the Medusa ransomware operation has now breached more than 500 US critical infrastructure organisations since June 2021, up from over 300 disclosed in March 2025. With a documented UK footprint and a habit of destroying backups, this is a recovery-posture problem for UK operators too.

CISA-confirmed Medusa critical infrastructure victims (US)
500 orgs375 orgs250 orgs125 orgs0 orgs300 orgsMar 2025 advisory500 orgsApr 2026 advisoryConfirmed CNI victims
View the data behind this chart
CISA-confirmed Medusa critical infrastructure victims (US)
Mar 2025 advisoryApr 2026 advisory
Confirmed CNI victimsorgs300orgs500

What CISA's updated advisory actually confirms

A joint advisory issued by CISA, the Department of Health and Human Services and the FBI states that as of April 2026, Medusa ransomware actors have impacted more than 500 victims across critical infrastructure sectors including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services, with further victims in medical, education, legal, insurance, technology and manufacturing.

This updates a March 2025 joint report that put the figure at over 300 critical infrastructure victims, meaning the confirmed US caseload has grown by roughly two-thirds in about a year.

Medusa itself dates back to January 2021 but only accelerated after 2023, when it launched the Medusa Blog leak site and shifted to a ransomware-as-a-service model. "Medusa developers typically recruit initial access brokers (IABs) in cybercriminal forums and marketplaces to obtain initial access to potential victims," the advisory notes, with affiliate payments ranging from $100 to $1 million on offer.

Why this isn't just a US bulletin for UK buyers

Medusa's reach already extends into the UK. HCRG Care Group, a UK private health and social care provider, was reportedly extorted for $2 million after Medusa claimed to have stolen 2.275TB of data. Gateshead Council was separately claimed by the group in January 2025, with a $600,000 demand tied to threats over stolen data.

Microsoft has also linked a Medusa-affiliated actor, tracked as Storm-1175, to high-velocity intrusions using both n-day and zero-day exploits, with concentrated impact on healthcare, education, professional services and finance across the UK, US and Australia. For anyone running zero trust architecture reviews, this is a directly relevant, currently active actor set — not a theoretical risk model.

How Medusa gets in: exposure and identity, not just malware

Reporting on Medusa's tradecraft describes a pattern of exploiting internet-facing assets and applications with known, unpatched vulnerabilities, alongside hijacking of legitimate accounts — sometimes handed off from initial access brokers. Microsoft's findings that Storm-1175 is particularly effective at locating exposed perimeter assets reinforce the point.

For operators with significant on-premise estates — VPN concentrators, remote access gateways, management interfaces — patch cadence and exposure reduction sit alongside endpoint defences as first-line controls. CISA's own guidance calls for network segmentation to block lateral movement and for blocking untrusted access to internal remote services, which aligns with a broader shift towards managed detection & response for organisations that can't monitor every internal segment themselves.

Illustration: Medusa Ransomware 2026: What UK CNI Buyers Must Do Now

The backup-destruction problem that should force an audit

Medusa has a documented history of deleting Windows Shadow Volume Copies and targeting backup-related files — VHD, .bak, .bkf and Windows Backup artefacts — specifically to remove the option of recovering without paying. Reporting also describes triple-extortion tactics layered on top of encryption and data theft to increase pressure on victims.

This matters enormously for on-prem estate operators whose recovery plan leans on domain-joined snapshots or a single connected backup repository. If Shadow Copies and local backup files are within reach of a domain-level compromise, they are within reach of Medusa. That's the argument for the modern 3-2-1-1-0 backup rule and genuinely immutable backup architectures rather than backups that are merely 'separate' in name.

What a backup and recovery audit should cover this quarter

Given the confirmed growth in Medusa's victim count and its specific targeting of recovery infrastructure, UK critical infrastructure and on-prem operators should treat backup validation as urgent, not routine housekeeping.

  • Confirm at least one immutable, offline or logically air-gapped copy exists outside domain-joined reach — see what are immutable backups
  • Run full restore tests, not just backup completion checks, since Medusa specifically targets restore-enabling files
  • Check whether Volume Shadow Copy Service and Windows Backup artefacts are your only recovery layer — if so, that's a single point of failure
  • Segment networks and restrict remote service access from untrusted origins, as recommended in CISA's advisory
  • Size backup and DR capacity against realistic downtime — try the backup and DR sizing calculator and calculate the cost of downtime

The bottom line for UK infrastructure buyers

A rise from 300+ to 500+ confirmed victims in roughly a year, a UK caseload that already includes a care provider and a local authority, and independent data showing only 37% of attacker actions get blocked once valid credentials are in play, together point to one conclusion: prevention alone is not the whole answer. Recoverability — proven, tested, and isolated from the domain that gets compromised — is the control that determines whether a Medusa intrusion becomes an incident report or a business-ending event. Reviewing backup and disaster recovery strategies against this specific threat behaviour is the practical next step for any UK operator with significant on-prem holdings.

Share
Key takeaways
  • CISA, HHS and FBI confirm Medusa ransomware has hit 500+ US critical infrastructure orgs since June 2021, up from 300+ in the March 2025 advisory.
  • Medusa has a documented UK footprint — HCRG Care Group and Gateshead Council — plus a Microsoft-linked affiliate (Storm-1175) active against UK, US and Australian targets.
  • Medusa deletes Windows Shadow Volume Copies and backup files (VHD, .bak, .bkf), directly undermining on-prem-only recovery strategies.
  • UK operators should prioritise immutable backups, restore testing and network segmentation now rather than after detection.
Frequently asked

FAQs — Medusa Ransomware 2026

How many organisations has Medusa ransomware hit?

CISA's joint advisory with HHS and the FBI states that as of April 2026, Medusa actors have impacted more than 500 victims across critical infrastructure sectors in the US, up from over 300 reported in a March 2025 advisory.

Has Medusa ransomware targeted UK organisations?

Yes. Reported UK victims include HCRG Care Group, a private health and social care provider, and Gateshead Council. Microsoft has also linked a Medusa-affiliated actor, Storm-1175, to intrusions in the UK, US and Australia.

Why does Medusa specifically target backups?

Medusa has a documented history of deleting Windows Shadow Volume Copies and backup-related files such as VHD, .bak and .bkf to remove victims' ability to recover without paying, which is why backup and disaster recovery strategies need independent, offline validation.

What should UK critical infrastructure buyers do first?

CISA recommends patching internet-facing systems, segmenting networks to block lateral movement, and blocking untrusted access to internal remote services, alongside verifying that backups are immutable and restore-tested.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111