Case study
Medusa encrypts a digital asset platform's operations database
Medusa encrypted the SQL Server backend and file server of a digital asset service provider, appending .MEDUSA, while its leak site ran a countdown threatening to publish KYC material. Cold wallets stayed offline and untouched; core data was recovered through page-level repair and log merging, with exposure scoping delivered in parallel.
- Industry
- Blockchain & Crypto
- Family
- Medusa
- Scenario
- Database Encrypted
- Handled
- 2026-08
This case study is composed from typical scenarios to illustrate our approach and the recovery paths involved. It does not describe a specific customer incident; real cases involving customer data are published only with authorization.
约 93%
Core backend data recovered
约 36 小时
Exposure assessment delivered
约 4 个工作日
Core systems back online
0
Ransom paid
Incident background
The client is a digital asset service provider running over-the-counter matching and custody operations. Its front-end matching service sits in the cloud; the operations backend — user accounts, order records, KYC review records and reconciliation ledgers — runs on a SQL Server instance on one on-premises Windows server; a separate file server holds KYC images and compliance review material.
Under internal controls, the bulk of assets sits in offline cold wallets with private keys split between hardware devices and paper backups, connected to neither the office network nor the backend.
Operations were outsourced to a small provider that reached internal hosts through one remote management product: never updated since deployment, its console mapped directly to the internet, its accounts without multi-factor authentication.
Early one weekend morning in August, duty staff found the backend unreachable. The database service had stopped; the mdf, ndf and ldf files and the file server's image directories all carried an appended .MEDUSA extension, and every directory held a note named !!!READ_ME_MEDUSA!!!.txt demanding contact within 48 hours via Tor live chat or Tox. The backup agent had been stopped, .bak files on the local backup disk were encrypted too, shadow copies had been purged, and no off-site or offline copy had ever been implemented. No contact was made, and once the 48-hour deadline lapsed the client's entry appeared on Medusa Blog: a public countdown, with screenshots of KYC material posted as a "sample".
What we did
Containment went out on the first call: hosts powered but off the network, no writes, no database restart, no "decryptor" trials, snapshot reclamation suspended. Automated withdrawals were paused and allowlist changes frozen; cold wallets stayed offline.
- Evidence and imaging. Read-only images of the backend and file server disks, plus surviving security logs, database error logs and remote management session records; later work ran on copies.
- Family confirmation and recoverability. The .MEDUSA extension, the !!!READ_ME_MEDUSA!!!.txt note and the 48-hour Tor/Tox demand identified Medusa — not the unrelated MedusaLocker — and no public decryptor exists. Surviving backups and snapshots proved unusable on validation; entropy mapping showed the large mdf/ndf files partially encrypted, with intact pages in the middle and tail.
- Recovery. Page-level scanning in an isolated environment rebuilt table structures; usable pages were extracted table by table into a fresh instance and unencrypted log replay filled in records up to the outage, reconciled three ways against on-chain deposit/withdrawal records, internal ledgers and user balances. KYC images came back from unencrypted remnants and a downstream read-only reporting copy.
- Funds check and hardening. Withdrawal approvals and on-chain transfers were reconciled item by item, confirming cold wallets and keys were untouched. The console's public mapping was removed and the product upgraded, credentials reset with MFA enabled, and a local-plus-offline immutable backup built and restore-tested.
- Deliverables. Recoverability assessment, data-gap list, exposure impact report, draft notification guidance, and a remediation checklist.
Recovery result
About 93% of the backend's core data was recovered: user accounts, order records and reconciliation ledgers returned to a point close to the outage, and business workflows ran normally on the new instance. What could not be recovered was a small volume of matching detail not yet committed that day, plus a handful of older KYC images — re-entered from cloud matching logs and statements, and re-collected from the users concerned. Core systems were back online in about four business days, with no ransom paid and no negotiation. Withdrawal approvals and signing records reconciled without anomalies; the cold wallets stayed offline throughout and were unaffected.
The exposure assessment was delivered in about 36 hours. The attacker had entered days before encryption through the internet-facing remote management console, stopped backup and security services, purged shadow copies and exfiltrated archives of KYC images and user ledgers. We scoped the categories and order of magnitude of personal information involved, advised on reporting and user-notification duties under the applicable rules, and recommended warnings to affected users about support-impersonation scams and identity misuse, plus tighter review of withdrawal anomalies. One point was stated plainly to the decision-makers: Medusa openly prices extensions, deletion and data purchase, and victims who paid have been approached again by supposed accomplices, so payment offers no assurance at all.
This is an illustrative case compiled from typical scenarios and anonymized; it does not refer to any specific client.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related content
Database Encrypted by Ransomware
When database files are encrypted, every business system that depends on them stops at once. This page explains how we triage an encrypted database, how recoverability is assessed, and when file repair, backup-plus-log restore, or rebuild is the right path.
Blockchain & Crypto
For blockchain firms, exchanges and custodians, mining operations and node providers, the attack surface sits almost entirely off-chain: nodes, index databases, KYC records and signing hosts are what actually get hit. This page covers the threat paths, a recovery approach built around key-custody audit and on-chain/off-chain reconciliation, and hardening priorities.
- No public decryptor
Medusa
Medusa appeared in June 2021 and shifted to a ransomware-as-a-service model from 2023, using the .MEDUSA extension and !!!READ_ME_MEDUSA!!!.txt note. It specialises in exploiting remote-management and file-transfer components such as ScreenConnect, Fortinet EMS and GoAnywhere, and applies pressure through a countdown clock with paid extensions.