Skip to content
Cyber Resilience & Data Security

Medusa Is Evolving. Cyber Resilience, Cyber Recovery, and ResOps Matter More Than Ever.

Why evolving ransomware demands tested, business-aligned recovery.


Key Takeaways 

  • The updated federal advisory documents new Medusa tactics, techniques, and more than 500 victims across critical infrastructure sectors. 
  • Attackers target more than production data; they also disrupt backups, identity, virtualization, and other systems organizations depend on for recovery. 
  • The advisory calls on organizations to prove their resilience through testing and validation against observed attacker behaviors, not assume it from plans or successful backup jobs alone.  

The latest federal advisory on Medusa ransomware was updated for a reason: The adversary changed. 

The updated federal advisory, issued August 18, 2026, by the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and U.S. Department of Health and Human Services (HHS), describes an adversary that recruits new access brokers, moves faster once inside, and has gotten better at making sure the damage it causes cannot be undone.  

The Attack Is Not Just Against Your Data

Medusa actors move quickly. Investigators report that Medusa actors have leveraged newly announced exploits within 24 hours and, in some cases, have used exploits up to a week before public vulnerability disclosure. 

Once inside, they blend in using legitimate remote management tools, credential theft, and living-off-the-land techniques. 

But the advisory’s most significant finding is that Medusa attacks the recovery path itself. 

The advisory maps this activity to MITRE ATT&CK technique T1490, Inhibit System Recovery. It documents the ransomware terminating services associated with backups, security, databases, communications, file sharing, and websites. It also deletes shadow copies, and remotely shuts down and encrypts virtual machines. 

If an attacker is deliberately targeting the systems, identities, and infrastructure an organization may need to recover, the problem extends beyond data protection into cyber resilience and cyber recovery. 

Where ResOps (Resilience Operations) Comes In

ResOps is not another name for backup. It is an operating discipline that brings security, IT, infrastructure, applications, operations, and the business together around one outcome: keeping critical services running and recovering them within the time the business can tolerate. 

The Medusa advisory never uses the word ResOps, but the thinking is there. It recommends organizations exercise, test, and validate their security programs against observed attacker behaviors, align security technologies to attack techniques, test them at scale, measure performance, and tune people, processes, and technologies based on the evidence. 

A backup does not prove it is clean. A recovery-time objective in a spreadsheet does not prove the business will be operating within that window. Resilience has to move from assumption to evidence. 

Start With the Business, Not The Server

The addition of HHS in the advisory makes this especially relevant for healthcare, a sector the FBI says has been a frequent Medusa target. The recovery conversation starts with three questions: 

  • What has to keep running, and what does minimum viable operation look like? 
  • Which identities, applications, infrastructure, and data support those services? 
  • Which recovery points we can trust, and what comes back first? 

In a hospital, leaving any one of those unanswered may mean a delayed surgery, a pharmacist who can’t verify a dosage, or a diagnostic system a clinician can’t trust. No single team can answer them alone, which is the gap ResOps is designed to close. 

Use Medusa to Test Your Assumptions

Use Medusa as a test case for recovery assumptions. Can an attacker reach the systems supporting recovery? What happens if Active Directory is compromised? Can you identify a clean recovery point, restore critical services in the correct order, and prove how long that will take? 

Threat actors adapt when defenders adapt. Resilience programs need to operate the same way: continuously tested, continuously validated, and continuously improved.  

Because the middle of an incident is a terrible time to discover that the recovery plan looked better on paper than it works in real life. 

FAQs

Q: What is Medusa ransomware? 

A: Medusa is a ransomware-as-a-service operation first identified in 2021. Its developers and affiliates use a double-extortion model, encrypting systems while threatening to publish stolen data if a ransom is not paid. 

Q: Why was the federal Medusa advisory updated? 

A: The August 2026 update incorporates findings from FBI investigations as recent as April 2026. It expands the documented tactics, techniques, procedures, exploited vulnerabilities, affiliate activity, and indicators of compromise, while adding HHS insights on attacks against healthcare. 

Q: How does Medusa threaten an organization’s recovery capabilities? 

A: Medusa can terminate services associated with backups, security, databases, communications, and other critical functions. It also can delete shadow copies, alter identity-related policies, and shut down or encrypt virtual machines, putting the recovery path itself at risk. 

Q: What should organizations do to help reduce Medusa risk? 

A: Organizations should patch known vulnerabilities promptly, segment networks, restrict access to remote services, strengthen authentication, monitor lateral movement, and apply least privilege. They also should maintain separate, offline, encrypted, and immutable recovery copies and regularly test restoration workflows. 

Q: What is ResOps, and how is it different from backup? 

A: ResOps, or resilience operations, is a cross-functional operating discipline – not a backup product. It aligns security, IT, infrastructure, applications, operations, business continuity, and business owners around restoring critical services within the amount of disruption the business can tolerate. 

Q: How can an organization help prove it is ready to recover? 

A: Start with critical business services, map the identities, applications, infrastructure, data, people, and third parties they depend on, and define successful recovery. Then run realistic exercises that identify clean recovery points, restore services in the correct order, measure actual recovery time, and turn any gaps into an owned improvement backlog. 

Chris Bevil is Principal Portfolio Marketing Manager at Commvault. 

More related posts


AI Data Resilience

Read more about AI Data Resilience