Jessica Entwistle
August 19 2026
CyberScoop reports that the FBI, CISA and the US Department of Health and Human Services have published an updated advisory on Medusa ransomware, detailing the group's tactics, techniques and procedures based on a year's worth of investigations. The advisory notes that Medusa has tallied hundreds of new victims since the previous guidance was issued, with significant targeting of healthcare organisations, critical infrastructure and other sectors. The updated guidance explains how the group gains initial access, typically through exploited vulnerabilities in internet-facing systems, compromised credentials or phishing, and what it does afterward, including lateral movement, credential harvesting, data exfiltration and deployment of ransomware payloads. The advisory also highlights Medusa's use of double extortion tactics, where stolen data is threatened with public release even if ransoms are paid. The group has demonstrated operational persistence and adaptability, continuing to refine its techniques and target organisations that may have gaps in basic security hygiene or incident response capabilities.
For UK organisations, particularly those in healthcare, local government, education and critical infrastructure, this updated guidance is a reminder that established ransomware groups remain persistent and operationally effective. Medusa's continued success reflects the reality that many organisations still have gaps in basic security hygiene, including unpatched internet-facing systems, weak or reused credentials and insufficient monitoring for lateral movement and data exfiltration. The healthcare sector remains a priority target, both because of the operational impact of disruption and because patient data has value on criminal markets. The fact that this is an updated advisory, not a new threat, underscores that defending against ransomware is not about responding to novel techniques but about consistently applying known defensive practices. Organisations that have experienced ransomware incidents often find that the root cause was not a sophisticated zero-day exploit but a failure to patch known vulnerabilities, enforce multi-factor authentication or detect lateral movement in a timely manner. The double extortion model also means that organisations must plan for both encryption and data exfiltration scenarios, and consider the reputational, regulatory and operational impact of sensitive data being published or sold.
Review whether your organisation has visibility into internet-facing assets, whether patching and vulnerability management processes are keeping pace with known exploits and whether there is effective monitoring for credential misuse and lateral movement. For healthcare and critical infrastructure organisations, consider whether incident response and business continuity plans account for both encryption and data exfiltration scenarios. Organisations should also evaluate whether there is clear ownership of ransomware preparedness, whether backup and recovery processes are tested regularly and whether there is a documented process for responding to extortion demands, including legal, regulatory and communications considerations. Consider whether network segmentation, privileged access management and endpoint detection and response capabilities are in place and operating effectively, and whether there is regular testing of incident response and recovery capabilities through tabletop exercises or simulations.
Source: CyberScoop