An advisory that took years of investigation to compile is only useful if the number on the front page changes how a security team behaves this week. This one should.
Five hundred victims and counting
CISA, the FBI and HHS have released an updated joint cybersecurity advisory on Medusa ransomware, building on one first issued in March 2025 and incorporating FBI investigations conducted as recently as April 2026. The headline figure is stark: more than 500 organisations have been compromised since Medusa first surfaced in June 2021. The sectors named are the ones that cannot simply absorb a ransomware outage and move on, healthcare and public health, the defence industrial base, critical manufacturing, government services and facilities, information technology, and financial services, with education, insurance and law firms also appearing among the victims.
Why the UK numbers stand out
Medusa operates in more than 45 countries, including Germany, France, Italy, Spain and the UK, but the UK is not just on the list, it is over-represented on it. Tracking data from earlier in 2026 shows Medusa accounts for roughly 9 percent of all reported ransomware victims in the UK, compared with about 2 percent globally. For a UK-based or UK-facing organisation, that is not a rounding error, it is a specific, elevated risk that generic ransomware guidance does not capture.
How Medusa actually gets in
Medusa does not rely on a single clever exploit. The group recruits initial access brokers on cybercriminal forums, reportedly paying between 100 dollars and 1 million dollars for working access to a target network, meaning the entry point is whatever that broker already has, a phished credential, an unpatched edge device, a misconfigured remote access tool. Once inside, Medusa runs a double-extortion model: victims get a 48-hour window to respond to the ransom note, after which the group starts contacting them directly and posts stolen data to a leak site with a visible countdown timer.
What the advisory changes for defenders
The updated advisory includes technical detection and mitigation guidance, but the operational takeaway is simpler than the technical detail: because Medusa buys its way in through brokers rather than a signature exploit, the defence that matters most is closing the everyday gaps those brokers sell, exposed remote access, stale credentials, and unpatched perimeter devices, before an access listing for your organisation ever goes up for sale.
If your organisation is in a sector this advisory names, or you are simply not confident your remote access surface is clean of the exposures Medusa’s brokers look for, contact Excello Digital. We help European organisations close the access gaps ransomware groups are actively buying and selling.
