Impact Analysis of Ransomware Attacks on EMEA Healthcare

July 23, 2026

By Assaf Morag, Cybersecurity Researcher

A ransomware attack against a hospital makes headlines. But the attack against other parts of the broader ecosystem including telemedicine providers, diagnostic laboratories, pharmacies, medical software vendors, public health authorities, and medical equipment suppliers rarely make the news, yet they can be just as devastating. 

To better understand the scope of this threat, we analyzed ransomware leak-site activity affecting healthcare organizations across Europe, the Middle East, and Africa (EMEA) between 2024 and 2026. The dataset reveals that ransomware groups are increasingly targeting the entire healthcare supply chain rather than focusing exclusively on hospitals. These attacks expose sensitive patient information, disrupt critical services, create downstream supply-chain risks, and can generate significant operational and financial consequences.

We examine healthcare-related ransomware disclosures collected by Flare, analyze the threat actors involved, review notable data exposure claims, investigate emerging targeting trends, and discuss the broader implications for healthcare organizations and their suppliers throughout the EMEA region.

Key Findings About Ransomware Attacks Against the EMEA Healthcare Sector 

  • Ransomware groups are targeting the full healthcare supply chain. Healthcare-related ransomware activity affects the entire healthcare supply chain, including hospitals, clinics, telemedicine providers, diagnostic laboratories, pharmacies, rehabilitation services, healthcare software vendors, staffing providers, medical equipment suppliers, and public-health agencies.
  • Threat actors increasingly target healthcare suppliers and service providers as a supply-chain entry point to reach larger healthcare ecosystems, as well as broader activity to monetize initial access and stolen healthcare data through leak sites, underground marketplaces, and secondary fraud schemes rather than relying solely on ransom payments.
  • In our sample we observed 14 threat actor groups (ransomware and extortion/hacktivist) targeting EMEA healthcare organizations in our sample, including 0apt, Qilin, NightSpire, LockBit 3.0, Gunra, The Gentlemen, RansomHub, DragonForce, Everest Ransom, Handala, 3AM, Kazu, WikiLeaks V2, and Global.
  • Exposed data indicates a broader scope than simply encrypt and extort operations. Several incidents involved substantial data exposure claims, including 40 TB and 450 million patient records allegedly claimed from American Hospital Dubai, 1.8 TB from Spire Healthcare, 578 GB from NRS Healthcare, and 110 GB from Genie Healthcare.
  • Analysis of Kazu activity suggests a growing concentration on healthcare organizations in recent months, despite the group’s earlier focus on government and public-sector targets. 
Flare CTA Block Preview

Healthcare Threat Intelligence

Detect Ransomware Threats Targeting Your Healthcare Organization and Supply Chain

Ransomware groups are targeting the full healthcare ecosystem: hospitals, suppliers, telemedicine providers, and staffing organizations. Flare continuously monitors ransomware leak sites, dark web forums, and illicit Telegram channels to detect when your organization, partners, or patient data appear in threat actor disclosures — before incidents escalate into major breaches.

Monitor ransomware leak sites and underground forums for mentions of your organization and supply-chain partners
Get early warnings on exposed credentials, patient data, and third-party vendor compromises
Start Free Trial

Healthcare Ransom Research: Scope and Methodology

This research focuses on ransom groups activity over the past two years, targeting health organizations in the EMEA region. We wanted to learn about the attack patterns, focus on significant groups, victims, and exposed data, compared  our findings to publicly disclosed data and financial and further fraud and scam implications.

Observed Incidents

Healthcare Ransomware Incidents

Healthcare Sector Ransomware Incidents

Observed attacks on healthcare organizations by threat actor group (2024–2026)

Date Organization Organization Activity Country Threat Actor Group
2026
May 2026 Clinica Digitale Telemedicine Italy Kazu
April 2026 MIMS Medical reference provider UK The Gentlemen
April 2026 Das Labor Diagnostic laboratory Austria The Gentlemen
February 2026 Ministry of Public Health Public health authority Qatar 0apt
February 2026 Health Service Executive National health service Ireland 0apt
February 2026 HCA Healthcare UK Private healthcare provider UK 0apt
February 2026 Spire Healthcare Hospital network UK 0apt
February 2026 Cleveland Clinic Abu Dhabi Hospital UAE 0apt
February 2026 Fresenius Medical Care Medical care provider Germany 0apt
February 2026 Clalit Healthcare organization Israel Handala
February 2026 Abrahamsom Center Healthcare/wellness center Israel NightSpire
2025
December 2025 THT Bio-Science Bio-science company France NightSpire
October 2025 London Women’s Clinic Fertility clinic UK Qilin
September 2025 American Hospital Dubai Hospital UAE Gunra
June 2025 American Hospital Dubai Hospital UAE Gunra
June 2025 Morpeth Pharmacy Pharmacy UK Global
April 2025 Sasszemklinika Eye clinic Hungary Qilin
March 2025 wieso-cert Healthcare/social-care Germany Qilin
March 2025 Genie Healthcare Healthcare staffing/data Ukraine Everest Ransom
March 2025 Los Madroños Hospital Hospital Spain Qilin
February 2025 NRS Healthcare Medical equipment supplier UK RansomHub
January 2025 hapsch.de Family doctor clinic Germany 3AM
January 2025 Al Tadawi Specialty Hospital Hospital UAE NightSpire
2024
July 2024 Hampden Veterinary Hospital Veterinary hospital UK DragonForce
July 2024 KBC Zagreb Healthcare provider Croatia LockBit 3.0
May 2024 rehab.ie Rehabilitation services Ireland LockBit 3.0
February 2024 Loran srl Software for Healthcare Italy WikiLeaks V2

Leaked healthcare data sold on Telegram (Flare link to post, sign up for the free trial to access if you aren’t already a customer) 

Supply Chain Targeting Pattern

Our dataset demonstrates that ransomware groups are targeting various healthcare types of companies that span across the entire sector. These attacks either focus specifically on the targeted organization (identified as high-pressure targets due to patient safety implications) or serve as a supply-chain vector to reach more vulnerable downstream targets such as hospitals. The latter depend heavily on continuous operations, patient trust, connected systems, electronic health records, third-party vendors, and distributed care environments. This operational dependency creates significant leverage for ransomware actors.

EMEA Healthcare Victim Disclosures by Threat Actor Group

EMEA Healthcare Victim Disclosures by Ransomware Group (2024–2026)

Ransomware Group
0apt
6
Qilin
4
NightSpire
3
The Gentlemen
2
Kazu
2
Gunra
2
LockBit 3.0
1
Global
1
Everest Ransom
1
RansomHub
1
3AM
1
Handala
1
WikiLeaks V2
1
0 1 2 3 4 5 6 7
Number of Victims

EMEA threat group distribution based on the healthcare victim’s disclosure

Ransom and Data Exposure Claims

Several leak entries contained explicit claims regarding the volume or sensitivity of stolen data. The most notable examples include:

  • American Hospital Dubai: 40TB and 450 million patient records
  • Spire Healthcare: 1.8TB leaked data
  • NRS Healthcare: 578GB leaked data
  • Genie Healthcare: 110GB of healthcare-related data, reportedly including employee records and IDs

Deep Dive: Kazu

Kazu is one of the smaller ransomware groups, but an interesting pattern emerged during our research, which originally uncovered the group’s attack on an Italian telemedicine organization. While reviewing several ransomware leak sites, we came across a number of fresh victim disclosures from Kazu, with all three recent victims from the healthcare sector. These victims from Latin America didn’t appear in our original dataset but drew our attention enough to further investigate this group and see how the activity in Latin America signaled a trend to what was also happening in EMEA.  

Screenshot of the recent victims of Kazu ransom group

Targeting Trend Analysis

To determine whether this was merely a coincidence or an indication of a broader targeting trend, we looked into the data further, which suggested that Kazu has increasingly focused on healthcare organizations over the past several months.

We analyzed 848 records collected by Flare, taken from ransom groups, hacker forums, and instant messaging activity. Kazu started its activity in mid-2025 and remains active. Kazu targeted a broad range of organizations across EMEA, Latin America, and South Asia. Government organizations represent the most common target profile, but healthcare has emerged as a close second.

Recent Ransom Postings by Sector

Kazu Victim Sectors by Quarter

Kazu Victim Sectors by Quarter

0 5 10 15 20
Q2 2025
Q4 2025
Q1 2026
Q2 2026
Government/Public Sector
Healthcare

Quantity of Kazu’s ransom postings by top sectors

As illustrated in the graph above, we cautiously assess that Kazu has increasingly focused on healthcare organizations over the past several months. While the dataset is relatively limited, the trend is notable: whereas the group’s earlier victim disclosures were largely concentrated in the public sector, its most recent victims have predominantly come from the healthcare industry. Although this does not conclusively prove an intentional targeting strategy, it strongly suggests a growing interest in healthcare organizations and healthcare-related data.

Operational Model: Hybrid Broker

The overwhelming majority of Kazu’s posts were focused on advertising stolen data, selling databases, or offering access to compromised systems rather than promoting ransomware negotiations or encryption services. 

The scale of the advertised compromises is particularly notable. Several victim posts within EMEA and outside referenced extraordinarily large data repositories: 

  • 12 TB allegedly linked to a Kuwaiti government organization
  • 3.8 TB from South Africa’s Gauteng Provincial Government
  • 2.9 TB from Colombia’s National Civil Service Commission
  • 2.3 TB from SaludTools
  • 1.8 TB from Natclar
  • 1.2 TB from Doctor Alliance

There are also references to the volume of stolen records which cumulatively is summed to approximately 30 million documents. 

These figures suggest that Kazu was not simply obtaining isolated databases but was repeatedly gaining access to large-scale repositories, backups, document management systems, and file servers containing years of accumulated organizational data. These compromises potentially expose personnel information, recruitment records, and operational documents, significantly increasing both intelligence and fraud risks.

Alongside victim disclosures, the dataset contains repeated references to administrative panels, FTP servers, government portals, dashboards, and other forms of network access being offered for sale. This behavior positions Kazu closer to a hybrid data broker and access broker than a traditional ransomware operator. The findings indicate that the group’s primary objective is the acquisition and monetization of high-value information at scale, transforming stolen healthcare, government, and citizen data into a long-term revenue stream through underground marketplaces and private buyers.

Financial Impact: What Healthcare Ransomware in EMEA Actually Costs

The broader implications of these incidents extend beyond individual organizations. Healthcare environments are highly interconnected ecosystems involving hospitals, suppliers, insurance providers, diagnostic services, telemedicine systems, cloud platforms, and public-health agencies. A ransomware intrusion against a single healthcare entity can therefore create cascading effects across regional healthcare delivery.

Additionally, healthcare data remains among the most sensitive forms of personal information. Leak site exposure involving patient records, employee data, HR files, internal communications, and operational documents can lead to regulatory investigations, reputational damage, financial losses, legal exposure, and long-term patient trust erosion.

The Change Healthcare Benchmark: $2.87 Billion in Damages

To understand the potential financial scale of healthcare ransomware, consider the most expensive incident on record. In February 2024, Change Healthcare, one of the largest healthcare payment processors in the US, was paralyzed by a ransomware attack that sent shockwaves through the medical system. The ransom group, ALPHV/BlackCat, infiltrated Change’s systems and exfiltrated over six terabytes of data, including sensitive health and financial records. The attack severely disrupted claims processing across the country, affecting an estimated 40% of all US medical claims and delaying prescription fulfillment, billing, and reimbursements nationwide. On top of the $22 million ransom payment, the attack caused immense operational and reputational damage with total damages costing approximately $2.87 billion. This equals the accumulated damage of the other six companies that appear on their list.

Europe’s Growing Financial Exposure

European institutions are increasingly quantifying healthcare cybersecurity costs:

  • The Coalition for Health, Ethics & Society paper highlights that healthcare experienced 289 cybersecurity incidents across the EU during 2024, which was more than any other essential sector, with the average major healthcare cyber incident estimated at approximately €300,000 per event, placing the cumulative financial impact in the billions annually. 
  • The European Central Bank (ECB), strongly argues that the true financial cost of ransomware is frequently underestimated because organizations focus too heavily on ransom payments themselves rather than secondary operational losses. The ECB highlights that incident response, forensic investigations, infrastructure restoration, legal obligations, regulatory scrutiny, third-party dependencies, and extended downtime often become the dominant cost drivers after an attack. This observation is particularly relevant for healthcare organizations, where downtime can directly affect patient treatment, diagnostics, scheduling systems, electronic health records, and emergency operations. 
  • Security vendor StationX estimates the average healthcare breach at approximately €10.3 million, with recovery efforts averaging €2.4 million per incident, and operational downtime costs reaching approximately €1.75 million per day during major disruptions. 

The Geopolitical Dimension 

An assessment by the European Parliamentary Research Service (EPRS) and a brief by the Coalition for Health, Ethics & Society state that ransomware attacks against hospitals should no longer be viewed solely as criminal incidents but increasingly as a broader operational and geopolitical threat to European resilience. 

Both reports highlight that many European healthcare institutions continue to rely on legacy technologies and fragmented IT environments that complicate patching, monitoring, and recovery operations. These institutions remain structurally vulnerable due to delayed implementation of security regulations, workforce shortages, and the rapid expansion of interconnected medical technologies. 

The consensus across these sources is that the true cost of healthcare ransomware in Europe stems primarily from operational disruption rather than ransom payments, as attacks against interconnected healthcare ecosystems in countries like Germany, the UK, the Netherlands and France can cascade across EHRs, medical devices, cloud services, and emergency operations, while fragmented legacy systems and poor interoperability significantly expand the attack surface and complicate incident response.

Recommendations for EMEA Healthcare Security Teams

Modern healthcare organizations face threats that extend far beyond their own networks. Many of the incidents identified in this research originated from third-party providers, software vendors, healthcare platforms, staffing organizations, and service providers that form part of the broader healthcare supply chain. As a result, healthcare security teams require visibility not only into their own attack surface but also into the external risks affecting their partners and suppliers.

Through continuous monitoring of ransomware leak sites, underground forums, messaging platforms, data marketplaces, exposed credentials, and emerging threat actor activity, healthcare organizations can gain early warnings that help them identify references to their suppliers and business partners as well as  brand, employees, subsidiaries, before incidents escalate into major breaches. 

While your partners and suppliers may be dealing with a severe cybersecurity intrusion, they often will not have the time or ability to provide an immediate warning. Yet that delay may be exactly the time attackers need to absorb, analyze, and sift through hundreds of gigabytes of stolen data in search of information, credentials, or relationships that can be leveraged against your organization. Blocking that door before it opens can make all the difference, potentially preventing losses worth billions of dollars and significantly strengthening an organization’s overall security posture.

For healthcare providers, CTI solutions can help identify early warning indicators such as stolen credentials, leaked patient-related data, discussions involving healthcare suppliers, compromised third-party vendors, exposed cloud assets, and ransomware actor targeting patterns. By combining external threat intelligence, supply-chain monitoring, and automated alerting, organizations can detect potential threats earlier, prioritize investigations, and reduce the operational impact of ransomware and data-extortion campaigns across the healthcare ecosystem.

Broader Implications for EMEA Healthcare

The ransomware activity observed across EMEA demonstrates that healthcare organizations remain among the most attractive targets for cybercriminal groups. The dataset highlights a shift away from attacks focused solely on hospitals toward broader campaigns targeting the entire healthcare ecosystem, including software providers, medical suppliers, diagnostic services, telemedicine platforms, staffing organizations, and public-health agencies.

This evolution significantly increases risk because a compromise affecting a single supplier can create downstream exposure for numerous healthcare organizations, patients, and business partners. Combined with the high value of medical data, operational dependencies, and strict regulatory requirements (particularly under GDPR and NIS2), healthcare organizations continue to provide ransomware operators with both financial leverage and long-term monetization opportunities.

The findings also illustrate that modern ransomware campaigns increasingly blend data theft, extortion, access brokerage, and information resale. As healthcare ecosystems become more interconnected, organizations must expand their security programs beyond internal assets and gain visibility into external threats, third-party risks, exposed credentials, ransomware leak sites, and emerging indicators of compromise throughout their supply chain.

Flare CTA Block Preview

Healthcare Threat Intelligence

Detect Ransomware Threats Targeting Your Healthcare Organization and Supply Chain

Ransomware groups are targeting the full healthcare ecosystem: hospitals, suppliers, telemedicine providers, and staffing organizations. Flare continuously monitors ransomware leak sites, dark web forums, and illicit Telegram channels to detect when your organization, partners, or patient data appear in threat actor disclosures — before incidents escalate into major breaches.

Monitor ransomware leak sites and underground forums for mentions of your organization and supply-chain partners
Get early warnings on exposed credentials, patient data, and third-party vendor compromises
Start Free Trial
Share article

Related Content

View All
07.21.2026

NULLZEREPTOOL: Inside a Telegram-Controlled DDoS and Multi-Function Attack Framework

07.20.2026

Strengthening Our Commitment to Responsible Threat Intelligence

07.20.2026

Stolen Healthcare Data Exists in the Gap of High-Value PII and Lower Sentences