CISA, HHS and the FBI have confirmed that the Medusa ransomware operation has now breached more than 500 US critical infrastructure organisations since June 2021, up from over 300 disclosed in March 2025. With a documented UK footprint and a habit of destroying backups, this is a recovery-posture problem for UK operators too.
View the data behind this chart
| Mar 2025 advisory | Apr 2026 advisory | |
|---|---|---|
| Confirmed CNI victims | orgs300 | orgs500 |
What CISA's updated advisory actually confirms
A joint advisory issued by CISA, the Department of Health and Human Services and the FBI states that as of April 2026, Medusa ransomware actors have impacted more than 500 victims across critical infrastructure sectors including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services, with further victims in medical, education, legal, insurance, technology and manufacturing.
This updates a March 2025 joint report that put the figure at over 300 critical infrastructure victims, meaning the confirmed US caseload has grown by roughly two-thirds in about a year.
Medusa itself dates back to January 2021 but only accelerated after 2023, when it launched the Medusa Blog leak site and shifted to a ransomware-as-a-service model. "Medusa developers typically recruit initial access brokers (IABs) in cybercriminal forums and marketplaces to obtain initial access to potential victims," the advisory notes, with affiliate payments ranging from $100 to $1 million on offer.
Why this isn't just a US bulletin for UK buyers
Medusa's reach already extends into the UK. HCRG Care Group, a UK private health and social care provider, was reportedly extorted for $2 million after Medusa claimed to have stolen 2.275TB of data. Gateshead Council was separately claimed by the group in January 2025, with a $600,000 demand tied to threats over stolen data.
Microsoft has also linked a Medusa-affiliated actor, tracked as Storm-1175, to high-velocity intrusions using both n-day and zero-day exploits, with concentrated impact on healthcare, education, professional services and finance across the UK, US and Australia. For anyone running zero trust architecture reviews, this is a directly relevant, currently active actor set — not a theoretical risk model.
How Medusa gets in: exposure and identity, not just malware
Reporting on Medusa's tradecraft describes a pattern of exploiting internet-facing assets and applications with known, unpatched vulnerabilities, alongside hijacking of legitimate accounts — sometimes handed off from initial access brokers. Microsoft's findings that Storm-1175 is particularly effective at locating exposed perimeter assets reinforce the point.
For operators with significant on-premise estates — VPN concentrators, remote access gateways, management interfaces — patch cadence and exposure reduction sit alongside endpoint defences as first-line controls. CISA's own guidance calls for network segmentation to block lateral movement and for blocking untrusted access to internal remote services, which aligns with a broader shift towards managed detection & response for organisations that can't monitor every internal segment themselves.

The backup-destruction problem that should force an audit
Medusa has a documented history of deleting Windows Shadow Volume Copies and targeting backup-related files — VHD, .bak, .bkf and Windows Backup artefacts — specifically to remove the option of recovering without paying. Reporting also describes triple-extortion tactics layered on top of encryption and data theft to increase pressure on victims.
This matters enormously for on-prem estate operators whose recovery plan leans on domain-joined snapshots or a single connected backup repository. If Shadow Copies and local backup files are within reach of a domain-level compromise, they are within reach of Medusa. That's the argument for the modern 3-2-1-1-0 backup rule and genuinely immutable backup architectures rather than backups that are merely 'separate' in name.
What a backup and recovery audit should cover this quarter
Given the confirmed growth in Medusa's victim count and its specific targeting of recovery infrastructure, UK critical infrastructure and on-prem operators should treat backup validation as urgent, not routine housekeeping.
- •Confirm at least one immutable, offline or logically air-gapped copy exists outside domain-joined reach — see what are immutable backups
- •Run full restore tests, not just backup completion checks, since Medusa specifically targets restore-enabling files
- •Check whether Volume Shadow Copy Service and Windows Backup artefacts are your only recovery layer — if so, that's a single point of failure
- •Segment networks and restrict remote service access from untrusted origins, as recommended in CISA's advisory
- •Size backup and DR capacity against realistic downtime — try the backup and DR sizing calculator and calculate the cost of downtime
The bottom line for UK infrastructure buyers
A rise from 300+ to 500+ confirmed victims in roughly a year, a UK caseload that already includes a care provider and a local authority, and independent data showing only 37% of attacker actions get blocked once valid credentials are in play, together point to one conclusion: prevention alone is not the whole answer. Recoverability — proven, tested, and isolated from the domain that gets compromised — is the control that determines whether a Medusa intrusion becomes an incident report or a business-ending event. Reviewing backup and disaster recovery strategies against this specific threat behaviour is the practical next step for any UK operator with significant on-prem holdings.
- 01BleepingComputer — CISA: Medusa ransomware hit over 500 critical infrastructure orgs · 19 August 2026
- 02The Register — Medusa ransomware infects 300+ critical infrastructure orgs, uses triple extortion · 13 March 2025
- 03BleepingComputer — Microsoft links Medusa ransomware affiliate to zero-day attacks · 1 January 2025
- 04The Register — Medusa extortion gang demands $2m from UK's HCRG Care Group · 20 February 2025
- 05The Register — Medusa ransomware group claims attack on Gateshead Council · 17 January 2025
- 06BleepingComputer — Ransomware gang sought BBC reporter's help in hacking media giant · 1 March 2026
- 07The Hacker News — Medusa ransomware on the rise from data leak site to triple extortion · 1 January 2024
