Desk live·
ForensicPost
Ransomware/Coverage/File 25-0314

Medusa Appeared Nowhere in This Corpus's First 520 Files

An operation with a joint federal advisory against it appeared nowhere in this corpus’s first 520 files. The reason is not that it was overlooked.

Constructed geometry · not a chart of case data
D. Kennedy11 min readConfidence: medium3 sources reviewed

Before 25-0312 this corpus contained no file on Medusa. It contained eleven on Cl0p, seven on LockBit and six on Akira. The gap was not a judgement about relative importance; nobody made a judgement at all.

How Coverage Actually Accumulated Here

Files were written by working sectors and periods and following what the reporting surfaced. A group whose victims are named in coverage of a large incident acquires files. A group whose victims are mostly small organisations that never make the news does not.

That is the same filter this database has documented from the outside — at 25-0502 on which incidents enter the record, at 25-0613b on the bias toward large organisations. It operates on the corpus itself, and it operated without anybody deciding anything.

The Advisory Is What Corrected It

Not a large incident. Medusa entered this database because three agencies published a document, and the document exists because investigators accumulated cases that individually generated no coverage.

Official advisories are, on this evidence, the only mechanism that surfaces an operation whose victims are individually too small to report on. That makes them disproportionately valuable to a database like this one, and there are not many of them.

What This Implies About The Rest

If a 300-victim operation could be absent from 520 files, other operations of comparable size are absent now. The corpus cannot name them, which is the whole difficulty.

The panel dump at 25-0517 pointed the same way from a different angle: an attacker’s own victim list looked nothing like the public record for the same period. Two independent routes to the conclusion that this database’s coverage is shaped by what gets written about rather than by what happens.

Filed Rather Than Fixed

This desk is not going to claim the gap has now been closed by two files. The standard set at 25-1114 is that recording thin coverage honestly beats omitting it, because omission reproduces the bias.

Graded medium: the observation about this corpus is verifiable by counting its own files, but the inference about what else is missing is, necessarily, an inference about things not present.

This is a coverage file

The file counts by brand are derived from this corpus’s own contents at the time of writing and can be checked against the published corpus export. The advisory it discusses is filed at 25-0312 with its sources. The inference about undocumented operations of similar size is an argument, not a finding. Corrections: corrections@forensicpost.com.

Sources
  1. #StopRansomware: Medusa ransomware (AA25-071A)CISA
  2. Medusa ransomware analysis, simulation and mitigation — CISA alert AA25-071APicus Security
  3. US-CERT alert AA25-071A (Medusa ransomware)SafeBreach
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary