Opens in a new tab

Healthcare Is Cybercrime’s Highest-Value Target: Ransomware, Exposure, and the Expanding Attack Surface

October 08, 2026

By Assaf Morag, Cybersecurity Researcher

Various healthcare and public health reports like the one of IC3 (2025) report that healthcare organizations are among the most targeted critical infrastructure sectors for cyber incidents, with hundreds of reports of ransomware attacks and data breaches reported in a single year. Underground Telegram channels that aggregate ransomware activity daily confirm the same pattern: across more than hundreds of attacks tracked over a two-month period, healthcare consistently appeared among the top five targeted sectors, with the United States accounting for nearly 80% of observed attacks.

The trend is not surprising, as healthcare combines four characteristics that threat actors consistently value highly:

  • Exceptionally sensitive personal and medical data
  • Extreme operational urgency
  • An industry moving trillions of dollars annually
  • Historically fragmented security environments

As a result, hospitals, clinics, insurers, pharmaceutical companies, laboratories, and medical device ecosystems increasingly sit at the intersection of financial fraud, cyber extortion, espionage, and even nation-state activity.

We examine the evidence supporting these trends through a combination of traditional research, industry reporting, and insights gathered from underground and cybercriminal communities which included capturing a snapshot of two months’ data from deep and dark web sites as well as Telegram channels.

Key Findings About the Healthcare Cyber Threat Landscape

  • Structural defender challenges compound the risk. Legacy systems that cannot be patched, shared clinical accounts, inconsistent MFA adoption, flat network architectures, constrained budgets, and a shortage of healthcare-specialized security talent create an environment where known vulnerabilities persist in production for years.
  • Healthcare is the most targeted critical infrastructure sector for ransomware in the United States. The FBI reported 460 ransomware attacks against healthcare in 2025. Flare’s analysis of underground Telegram channels tracking ransomware activity across more than 1,700 attacks over two months confirms healthcare’s consistent presence among the top targeted sectors, with groups including Qilin, Akira, and DragonForce among the most active operators.
  • Medical records are uniquely valuable to attackers because they cannot be reissued. Unlike credit card numbers, a stolen patient identity combining full PII, insurance details, clinical history, prescription data, and biometric information can be monetized for years through fraud, insurance abuse, identity theft, phishing, and blackmail. This makes healthcare data among the most expensive on illicit markets.
  • The attack surface is expanding faster than defenses can adapt. Internet of Medical Things (IoMT) devices (infusion pumps, imaging systems, patient monitors), AI-powered clinical tools, cloud-connected SaaS platforms, and sprawling third-party vendor ecosystems are all creating new entry points that many healthcare organizations lack the visibility and resources to secure.
  • Healthcare fraud extends well beyond ransomware. Underground forums advertise unauthorized access to medical transportation platforms, insurance billing systems, and patient management portals. One observed listing allegedly offered administrative access to a US non-emergency medical transportation platform used for Medicaid billing, patient data management, and integrations with Uber Health and Lyft, enabling “ghost billing” fraud at scale.
Flare CTA Block Preview

Identity-First Cyber Threat Intelligence

Detect When Your High-Value Data Surfaces on the Dark Web

Sophisticated threat actors concentrate where value is high and legal deterrence is low, especially with PHI. Flare continuously monitors dark web marketplaces, forums, and illicit Telegram channels to detect when your organization’s most sensitive data appears for sale, before it’s weaponized.

✓ Continuous monitoring across dark web markets where high-value PHI is bought and sold
✓ Real-time alerts when your organization’s data, credentials, or patient records are exposed
Start Free Trial

The Evidence from Cybercrime Communities

We have observed significant evidence that threat actors increasingly view the healthcare sector as one of the most attractive and strategically valuable targets in the cybercriminal ecosystem. This trend is reflected across underground communities, including Telegram channels dedicated to tracking ransomware activity and publishing daily aggregations of attacks, where healthcare organizations consistently appear among the most frequently targeted sectors.

A daily “darkfeed” about ransomware and breach activity (Flare link to post, sign up for the free trial to access if you aren’t already a customer)

When analyzing aggregated ransomware reporting over a two-month period covering more than 1,700 attacks, the trend becomes both clear and difficult to ignore: healthcare consistently emerges as one of the most heavily targeted sectors across the cybercriminal landscape.

Top five targeted sectors according to the Telegram channel (two months’ data)

When examining the most targeted countries across the dataset, the trend is both clear and consistent across our data sample. The United States overwhelmingly dominates the targeting landscape, accounting for nearly 80% of observed attacks, while other highly developed countries consistently appear among the most frequently targeted regions. This trend is consistent with what we observed with infostealer malware targeting the healthcare industry (see our State of Healthcare Credential Exposure Report in 2026).

Top five targeted countries according to the Telegram channel (two months’ data)

This dataset spans activity across major ransomware and data extortion operations, with groups such as Qilin, The Gentleman, Akira, DragonForce, and LockBit ranking among the most active threat actors observed during the analysis period.

Our findings are further reinforced by a growing body of academic research, government reporting, and industry publications highlighting the healthcare sector as one of the most heavily targeted and strategically valuable sectors within the modern cyber threat landscape, including:

  • The FBI’s 2025 Internet Crime Report identified healthcare and public health as the most targeted critical infrastructure sector for cyber incidents in 2025, with 460 ransomware attacks and 182 data breaches.
  • ENISA has consistently identified ransomware as one of the most significant cyber threats facing healthcare. Its 2023 Health Threat Landscape found that ransomware accounted for 54% of analysed healthcare incidents, with patient data (including electronic health records) among the most frequently targeted assets. More recent ENISA analysis found that ransomware still accounted for 45% of health-sector incidents analysed in its 2024 threat landscape.

Why Healthcare is Such a High-Value Target

Healthcare organizations store unusually rich datasets, including:

  • Full identity information
  • Insurance and billing records
  • Medical histories
  • Prescription data
  • Biometric information
  • Clinical research and intellectual property
  • Employee credentials
  • Connected medical device telemetry

PHI is the most expensive PII on the dark web for two main reasons: Unlike credit cards, medical records cannot easily be “reissued.” A stolen patient identity may remain useful for years in fraud schemes, insurance abuse, identity theft, phishing, or blackmail.

In addition, health records can enable various compounding attack vectors for insurance and prescription fraud, and leverage in targeted extortion.

Healthcare environments also often prioritize availability over strict security controls. Systems must remain operational for patient care, which creates difficult tradeoffs around patching, downtime, segmentation, and legacy infrastructure.

Main Threat Categories

Ransomware

Ransomware remains one of the most significant operational threats facing the healthcare sector, targeting hospitals, imaging centers, pharmacies, ambulance systems, regional health networks, and third-party providers.

Attackers commonly gain access through phishing campaigns, stolen credentials, exposed RDP services, vulnerable VPN infrastructure, third-party vendor access, and unpatched edge devices.

The impact frequently extends far beyond IT disruption, leading to delayed surgeries, inaccessible medical records, medication-dispensing failures, diagnostic delays, and the diversion of emergency patients. Increasingly, research also links ransomware-induced hospital disruption to measurable patient harm. In addition to a BBC report from 2025 supports this claim, a US study from 2023 found that in-hospital mortality among Medicare patients rose from roughly 3% to 4% during ransomware attacks, estimating that such incidents contributed to 42–67 additional deaths between 2016 and 2021. A more recent study (2026) found that in-hospital mortality among patients already admitted when an attack began increased by 34–38%.

Because healthcare organizations operate in highly time-sensitive environments where downtime directly affects patient care, threat actors often view the sector as more likely to comply with extortion demands in order to rapidly restore operations.

A screenshot taken from the BreachForums

The response to a healthcare organization’s leak on the ShinyHunter’s breach forum website, illustrating this data is valuable to some threat actors

Data Breaches and Leaks

Healthcare data breaches increasingly stem from a combination of credential theft, cloud misconfigurations, and third-party supply chain exposure. Attackers frequently leverage infostealer malware to obtain staff credentials, browser cookies, session tokens, MFA artifacts, and saved passwords, enabling unauthorized access to healthcare systems without directly exploiting hospital infrastructure.

At the same time, misconfigured cloud environments such as exposed storage buckets, databases, weak API authentication, overly permissive identity controls, and internet-facing telemetry dashboards continue to unintentionally expose sensitive patient data across platforms supporting EHR systems, imaging, telemedicine, scheduling, insurance processing, and AI-driven diagnostics.

The sector’s heavy dependence on third-party vendors, including SaaS providers, laboratory systems, imaging platforms, device manufacturers, and managed service providers further amplifies risk, as a single upstream compromise can cascade across hundreds of downstream healthcare organizations and impact millions of patients simultaneously.

A threat actor is looking for Brazilian healthcare insurance and healthcare companies’ data (Flare link to post, sign up for the free trial to access if you aren’t already a customer)

Medical Devices and IoMT Risks

The rapid adoption of the IoMT has significantly expanded the healthcare attack surface by connecting infusion pumps, MRI and CT systems, patient monitors, smart beds, implant telemetry platforms, and wearable devices directly to hospital networks and cloud-connected environments.

Many of these systems operate on outdated operating systems, rely on embedded or legacy firmware, cannot be easily patched, and often lack strong authentication or network segmentation controls. In practice, healthcare environments frequently depend on flat or highly interconnected networks, allowing a compromise in one device or system to potentially impact broader clinical operations.

As a result, attacks against IoMT infrastructure can create not only operational disruption but also direct patient safety concerns, particularly when diagnostic systems, monitoring equipment, or treatment-delivery devices become unavailable, manipulated, or inaccessible during clinical care.

In the screenshot below, there is an underground post that shows several examples of real-world risks and consequences of healthcare data breaches. Along these actively exploited risks there’s also some discussion about attacking IoMT devices, while it is still largely confined to theoretical discussion based on research demonstrations, it could evolve to a relevant active threat in the near future.

A Bluetooth DoS technique (BlueSmack) is discussed in the context of medical devices attacks (Flare link to post, sign up for the free trial to access if you aren’t already a customer)

Fraud and Scams

Healthcare organizations are increasingly targeted by a wide range of fraud and scam operations that exploit both patients and healthcare personnel through phishing campaigns, insurance fraud, fake billing schemes, business email compromise (BEC), impersonation attacks, and fraudulent healthcare portals or payment systems. Threat actors frequently abuse trusted healthcare branding to distribute malware, steal credentials, harvest insurance information, or redirect financial transactions. Patients are often targeted through fake appointment notifications, prescription scams, and medical-payment phishing campaigns.

The growing digitization of healthcare services, combined with sensitive personal and insurance data, makes the sector particularly attractive for financially motivated cybercriminals seeking identity theft, reimbursement fraud, account takeover, and large-scale social engineering opportunities.

Hackers exploiting medical transportation systems for fraud and patient data theft (Flare link to post, sign up for the free trial to access if you aren’t already a customer)

In the example above, there’s an advertisement of alleged unauthorized administrative access to a US Non-Emergency Medical Transportation (NEMT) platform used to manage patient transportation, provider onboarding, billing, and integrations with services like Uber Health and Lyft. The primary fraud model described is healthcare “ghost billing,” where attackers could create fake provider accounts, mark non-existent trips as completed, and submit fraudulent reimbursement claims to Medicaid or insurers while also monetizing sensitive patient and insurance data. If genuine, this would represent a severe healthcare cybercrime incident involving operational abuse, medical identity fraud, financial fraud, and large-scale exposure of protected patient information.

Who are the Attackers?

The healthcare sector attracts a broad spectrum of threat actors ranging from financially motivated cybercriminal groups to sophisticated nation-state operators.

Cybercriminal Organizations

These groups primarily target healthcare institutions for ransomware, fraud, credential theft, extortion, and large-scale data monetization, often exploiting phishing campaigns, exposed remote services, stolen credentials, third-party access, and vulnerable internet-facing infrastructure. The sector’s operational sensitivity and reliance on continuous availability make hospitals and healthcare providers particularly attractive for extortion-driven attacks, as disruptions can directly impact patient care and increase pressure to restore systems quickly.

Nation-State Espionage Operations

Healthcare has become strategically valuable for nation-state espionage operations due to the concentration of sensitive medical, scientific, and public health information within the sector. This threat has been demonstrated in multiple publicly attributed campaigns. In 2020, U.S., UK, and Canadian authorities attributed attempts to steal COVID-19 vaccine development and testing information to APT29 (Cozy Bear), which they assessed to operate as part of the Russian intelligence services.

Targets include vaccine research, pharmaceutical intellectual property, genomic databases, clinical research, biotechnology innovation, and public health information that can support geopolitical, economic, intelligence, or strategic objectives.

Chinese state-linked actors have demonstrated similar targeting, when US authorities have accused APT40, operating on behalf of China’s Ministry of State Security, of targeting biomedical, healthcare, and virus-research organizations, while APT10 campaigns have compromised organizations in the healthcare and biotechnology sectors. US intelligence has also warned that genomic databases are attractive targets for cyber theft and assessed that China has obtained US health and genomic information through investments, acquisitions, and cyber breaches.

During global crises such as pandemics or large-scale public health emergencies, healthcare and life-sciences organizations can become even more attractive targets. The COVID-19 pandemic provided a clear example, with the UK’s National Cyber Security Centre observing that hostile states shifted cyber operations toward stealing vaccine and medical research while organizations were operating under exceptional pressure. The combination of strategically valuable research, accelerated development programs, and heightened operational urgency creates opportunities for both espionage and disruptive cyber operations.

AI and Emerging Healthcare Risks

The rapid adoption of artificial intelligence across healthcare environments is introducing a new layer of security, privacy, and governance challenges. Healthcare organizations are increasingly integrating AI copilots, large language model (LLM) assistants, medical transcription systems, AI-assisted diagnostics, autonomous scheduling platforms, and intelligent triage workflows into daily clinical and administrative operations. These technologies often require broad access to sensitive patient information, internal documentation, medical imaging, operational systems, and clinical communications in order to function effectively. As AI systems become more deeply embedded into healthcare workflows, they are transforming not only how data is processed, but also how information flows across cloud services, third-party platforms, and interconnected healthcare ecosystems.

AI adoption expands the attack surface and introduces risks that many healthcare organizations are not yet prepared to govern:

  • Excessive data access privileges granted to AI systems that interact with patient records
  • Weak identity boundaries between AI systems and human users
  • Prompt injection attacks targeting clinical AI tools
  • Unintended exposure of sensitive patient information through AI integrations and third-party AI providers
  • Shadow AI usage by employees connecting unapproved AI tools to clinical workflows
  • Limited visibility into where patient data travels once AI tooling is integrated, creating uncertainty around compliance, access control, and data residency

Healthcare Sector Defenders’ Side Challenges

Defending modern healthcare environments has become increasingly difficult as organizations balance cybersecurity requirements against operational continuity, patient safety, regulatory obligations, and limited resources.

Unlike many other sectors, healthcare providers must secure highly interconnected ecosystems that combine legacy infrastructure, cloud platforms, medical devices, third-party vendors, and rapidly expanding digital services.

As attackers continue to evolve their techniques, many healthcare organizations are struggling to modernize security controls quickly enough to match the growing complexity and scale of the threat landscape.

Legacy Technology and Infrastructure

Many healthcare organizations continue to rely on outdated infrastructure that was not designed to withstand modern cyber threats. Hospitals frequently operate legacy Windows systems, unsupported medical software, outdated communication protocols, and flat network architectures that increase the potential impact of lateral movement during an intrusion. In many cases, medical devices and clinical systems cannot be easily patched or upgraded due to vendor dependencies, certification requirements, operational concerns, or fears of disrupting patient care. This creates long-term exposure where vulnerable systems remain active in production environments for years.

Identity and Access Weaknesses

Identity security remains a major challenge across healthcare environments. Common issues include shared accounts, weak or inconsistent MFA adoption, excessive user privileges, and broad third-party contractor access to sensitive systems. As healthcare ecosystems increasingly depend on SaaS platforms, cloud services, external laboratories, and managed service providers, identity becomes one of the most critical attack surfaces. Threat actors frequently exploit stolen credentials, session tokens, and poorly governed third-party access to bypass traditional perimeter defenses and gain persistent access into healthcare networks.

Operational and Clinical Constraints

Unlike many other industries, healthcare organizations must constantly balance cybersecurity improvements against patient safety and clinical continuity. Security changes can interfere with medical workflows, impact device certifications, disrupt vendor support agreements, or introduce delays in critical care environments. As a result, security teams often operate under strict operational limitations that slow remediation efforts, reduce patching flexibility, and complicate the deployment of modern defensive controls across clinical systems and medical devices.

Visibility and Monitoring Gaps

Many healthcare environments still lack comprehensive visibility into their digital infrastructure. Organizations frequently struggle with incomplete asset inventories, limited cloud visibility, insufficient east-west network monitoring, and poor telemetry from medical or IoMT devices. This makes it difficult for defenders to accurately identify exposed systems, detect suspicious lateral movement, or understand the full scope of an incident once attackers gain access. In highly interconnected healthcare ecosystems, these visibility gaps can significantly delay detection and response.

Resource, Funding, and Talent Challenges

Healthcare organizations also face broader structural challenges related to funding and cybersecurity staffing. Many providers operate under constrained budgets while competing against rapidly evolving threats that require specialized expertise in cloud security, identity management, incident response, medical device security, and threat intelligence. The shortage of experienced cybersecurity professionals within healthcare further limits the ability of organizations to mature their security operations and maintain continuous monitoring.

What Healthcare Security Teams Should Take from this Article

Healthcare has become one of the most aggressively targeted sectors in the modern cyber threat landscape due to the combination of highly sensitive data, operational urgency, interconnected digital ecosystems, and expanding attack surfaces.

Ransomware, credential theft, fraud, supply chain compromise, cloud exposure, IoMT vulnerabilities, and AI-driven risks are converging to create an increasingly complex environment for defenders.

At the same time, many healthcare organizations continue to face structural limitations including legacy infrastructure, fragmented visibility, operational constraints, staffing shortages, and growing dependence on third-party platforms and cloud-connected services. As healthcare continues its rapid digital transformation, organizations must adapt their security strategies to address not only traditional cyber threats, but also emerging risks associated with AI adoption, identity-centric attacks, and interconnected healthcare ecosystems.

Flare CTA Block Preview

Identity-First Cyber Threat Intelligence

Detect When Your High-Value Data Surfaces on the Dark Web

Sophisticated threat actors concentrate where value is high and legal deterrence is low, especially with PHI. Flare continuously monitors dark web marketplaces, forums, and illicit Telegram channels to detect when your organization’s most sensitive data appears for sale, before it’s weaponized.

✓ Continuous monitoring across dark web markets where high-value PHI is bought and sold
✓ Real-time alerts when your organization’s data, credentials, or patient records are exposed
Start Free Trial

Share article