Healthcare — Cyber Threat Activity
Healthcare is the sector where cyber attacks translate most directly into physical harm, and it carries more than 2,100 recorded incidents across 77 countries in our log. Over 630 fall in the trailing 180 days and 90 distinct groups have been attributed at least one claim, led by Qilin (170), INC Ransom (119), RansomHub (80), LockBit (78) and The Gentlemen (48). CISA, FBI and HHS have warned since 2020 that criminal crews deliberately target hospitals with loader-to-ransomware chains, accepting that the consequence is diverted ambulances, delayed procedures and clinicians reverting to paper. The economics are brutal and well understood by the attackers: a hospital cannot suspend operations to rebuild, holds decades of irreplaceable records, and faces regulatory exposure on disclosure, so it is squeezed from three directions at once. Our records reach back to 2010, earlier than most sectors here, because healthcare incidents arrive through public breach notification regimes as well as leak-site claims, which also explains why the United States accounts for 1,688 of them; that is a reporting-law artefact, not evidence that American hospitals are uniquely targeted. India, Canada, the United Kingdom, Australia and Germany follow. Medical devices and imaging systems deepen the problem, since certified equipment often cannot be patched on any normal cycle and sits on the same network as everything else. Treat the totals as claims rather than confirmed breaches, and note that the sector's real exposure runs wider than the count: third-party billing, transcription and diagnostics providers concentrate patient data far beyond the walls of any one hospital, and a single supplier compromise routinely surfaces later as dozens of separate provider notifications.
- Recorded incidents: 2,498
- Incidents, trailing 180 days: 760
- Tracked threat actors: 184
- Malware families: 225
Recent incidents
- Great Bay Bio 2026-09-20
- MPA Pharma 2026-09-18
- AstraZeneca Türkiye 2026-09-18
- PITTSRAD 2026-09-18
- hygear.com 2026-09-18
- Beckman Coulter, Inc 2026-09-17
- Diakoniewerk Apolda gGmbH 2026-09-17
- Owen Leigh Optometry 2026-09-16
- Hattiesburg Eye Clinic 2026-09-15
- Apteki Mareshki 2026-09-15
- MedSkin Solutions Dr. Suwelack AG 2026-09-15
- PANTHERx Rare 2026-09-15
- triniticaring.org 2026-09-15
- Metropolitan Community Health Services 2026-09-14
- Ibn Sina Trust 2026-09-12
- Imperial Healthcare Solutions 2026-09-11
- Mankato Clinic 2026-09-10
- On Demand Occupational Medicine 2026-09-10
- General Santos Doctors Hospital 2026-09-10
- PharmaEssentia Corporation 2026-09-09
Threat actors targeting Healthcare
- Qilin 191 incidents
- INC Ransom 131 incidents
- LockBit 88 incidents
- RansomHub 83 incidents
- The Gentlemen 62 incidents
- SafePay 53 incidents
- Akira 47 incidents
- Medusa Ransomware 44 incidents
- KillSec 43 incidents
- Rhysida 43 incidents
- BianLian 41 incidents
- DragonForce 40 incidents
- Hunters International 29 incidents
- NightSpire 26 incidents
- Cl0p 24 incidents
- BlackSuit 22 incidents
- Lynx Ransomware 19 incidents
- Krybit 15 incidents
- Anubis 14 incidents
- Dire Wolf 14 incidents
- PEAR Team 13 incidents
- CRPxO 13 incidents
- ShinyHunters 13 incidents
- Black Basta 12 incidents
Where these victims are
- United States 1,868
- India 48
- Germany 42
- Canada 40
- United Kingdom 39
- Australia 33
- Brazil 22
- France 19
- Mexico 17
- Spain 17
- Italy 14
- Switzerland 14
Malware used against Healthcare
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Agent Tesla Malware
- Akira Malware
- Black Basta Malware
- BlackCat Malware
- Clop Malware
- Cobalt Strike Malware
- Conti Malware
- Emotet Malware
- Impacket Tool
- Lumma Stealer Malware
- Metasploit Tool
- Mimikatz Tool
Coverage. 94.9% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.