Cybersecurity in Healthcare: A Growing C-Suite Concern

0
32

Key Takeaways

  • The healthcare industry is facing increased cybersecurity threats due to rapid digitization and interconnectedness, with email being the top threat vector (85% of all detections) and the U.S. being the biggest target (75% of all detections).
  • The "cascading effect" of cyberattacks is causing a chain reaction that paralyzes other systems, resulting in lethal consequences for patients.
  • Ransomware gangs are targeting the healthcare sector, with groups like Qilin, INC Ransom, and Sinobi using various tactics to exploit vulnerabilities.
  • The use of extortion-only tactics is on the rise, with 12% of all attacks on healthcare organizations involving solely extortion, a 300% increase from 2023.
  • Phishing remains the primary vector for initial access, with hackers using themes like "AI Transformation" and "Regulatory Compliance" to lure IT administrators.

Introduction to Healthcare Cybersecurity Threats
The healthcare industry is facing a growing number of cybersecurity threats due to rapid digitization and increasing interconnectedness. According to a report by Trellix, the industry is "exposing clinical technology to threats it was never engineered to withstand." The report, which analyzed 54.7 million detections from Trellix products in healthcare environments in 2025, highlighted the top threat vectors and targets in the industry. Email was found to be the top threat vector, accounting for 85% of all detections, while the U.S. was the biggest target, accounting for 75% of all detections.

The Cascading Effect of Cyberattacks
The "cascading effect" of cyberattacks is a major concern for the healthcare industry. This refers to the chain reaction that occurs when a disruption to one system causes a chain reaction that paralyzes other systems. According to Trellix, this was the "defining trend of 2025" in healthcare cybersecurity. The consequences of these attacks can be lethal, with research showing that cyberattacks that cripple hospital computer systems can result in increased mortality rates and other patient harms. As Trellix vice president of threat intelligence strategy John Fokker noted, "cyber incidents are no longer an IT disruption. They are a patient safety crisis."

Ransomware Gangs Targeting the Healthcare Sector
Ransomware gangs are increasingly targeting the healthcare sector, exploiting its vulnerabilities and using various tactics to extort money from organizations. Qilin, for example, "matured into a high-tempo operation" in 2025, using Linux- and ESXi-based malware to target databases storing electronic health records. Another group, INC Ransom, launched 34 attacks on healthcare organizations in 2025, nearly 10% of the annual total. Other groups, such as Sinobi and Devman2, have also established dangerous reputations, with Sinobi focusing on biotechnology firms and other specialized healthcare companies, and Devman2 notorious for massive data exfiltration.

Extortion-Only Tactics on the Rise
The use of extortion-only tactics is on the rise in the healthcare sector, with 12% of all attacks on healthcare organizations involving solely extortion, a 300% increase from 2023. This shift reflects the sector’s unique concerns about the exposure of private data. By demanding relatively small amounts of money, typically between $50 to $500 per patient, ransomware gangs can bypass corporate insurance and legal teams, speeding up the process of getting paid. This tactic is particularly effective in the healthcare sector, where the exposure of private data can have serious consequences for patients and organizations.

Threat Actors’ Tactics
Threat actors are using a range of tactics to breach healthcare organizations, with phishing remaining the primary vector for initial access. According to Trellix, phishing accounted for 89% of incidents, with hackers using themes like "AI Transformation" and "Regulatory Compliance" to lure IT administrators. Hackers are also using malicious domains with healthcare terms like "HIPAA," as well as malicious subdomains built into legitimate healthcare websites, to establish command-and-control infrastructure. These tactics are designed to exploit the vulnerabilities of healthcare organizations and gain access to sensitive data.

Conclusion
In conclusion, the healthcare industry is facing a growing number of cybersecurity threats, with ransomware gangs and other threat actors exploiting its vulnerabilities and using various tactics to extort money from organizations. The "cascading effect" of cyberattacks is a major concern, with lethal consequences for patients. The use of extortion-only tactics is on the rise, and threat actors are using a range of tactics to breach healthcare organizations. It is essential for healthcare organizations to take proactive steps to protect themselves against these threats, including implementing robust cybersecurity measures and educating IT administrators about the latest tactics used by threat actors.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here