Matt Johansen @mattjay.com · Sep 29

Group referenced previous "successful" insider compromises at UK healthcare and US emergency services orgs. Claims align with known Medusa TTPs focusing on high-value targets.

4 likes 1 replies

?

Replies

Matt Johansen · Sep 29

Worth noting actors maintained professional demeanor throughout most interactions. Only escalated to aggressive tactics (MFA bombing) after patience wore thin. Even apologized and said that was just them testing the login page.