Meet us a Black Hat! Become a Black Kite Ranger to help protect the cyber ecosystem.Learn more
BlackKite: Home
Menu
gradient ecosystem background

Healthcare Under Ransomware Attack

Healthcare Climbed to 3rd Most Targeted Industry in 2024

Healthcare Under Ransomware Attack: Why Healthcare Is Now the 3rd Most Targeted Industry in the Ransomware Cybercrime Ecosystem

by the Black Kite Research Group™

Healthcare is now the third most targeted industry in the ransomware landscape. That's not a projection. It's the documented outcome of two years of structural change in how ransomware groups recruit, operate, and select targets. Ransomware incidents hitting healthcare organizations climbed from 5% to 8% of all attacks globally between 2023 and 2024. That 32% year-over-year increase pushed the sector past Professional Services and into the top three for the first time. The sector's own defenses didn't weaken. The ecosystem that targets it got more aggressive.

The event that accelerated this shift was the Change Healthcare attack in February 2024. When a disputed ransom payment left a BlackCat/AlphVM affiliate unpaid, it exposed a structural tension that had been building inside the ransomware-as-a-service model for years. Affiliates responded by renegotiating their relationships with groups, demanding higher payout splits, and targeting sectors where operational urgency creates the fastest path to payment. Healthcare checked every box. The Black Kite Research Group™ tracked the forces that made this shift possible, the new groups that emerged to exploit it, and the specific technical and operational vulnerabilities that put healthcare organizations in the crosshairs.

The data is specific. Healthcare ransomware victims who had experienced a prior attack saw a 27% increase in repeat incidents. HHS breach disclosures more than doubled from 2023 to 2024. Small practices accounting for 25% of all healthcare ransomware victims confirms that attackers aren't filtering by organization size. They're filtering by exploitability. The Ransomware Susceptibility Index® (RSI™) recorded three separate risk escalations in Change Healthcare's infrastructure between mid-2023 and the attack date. Each escalation was a remediable signal. None were acted on.

This report is your blueprint for understanding what changed in the ransomware ecosystem, why healthcare is now a primary target, and what an early warning defense posture looks like in practice.

(No download required)

Key Findings From the 2025 Healthcare Under Ransomware Attack Report

Healthcare Climbed From 5th to 3rd Most Targeted Industry With Incidents Rising 32% Year Over Year

Ransomware incidents targeting healthcare organizations rose from 5% to 8% of all global attacks between 2023 and 2024. The sector moved past Manufacturing and Technical Services, landing just behind Construction and Government in total targeting frequency. The climb correlated directly with two ecosystem-level events: the Change Healthcare attack in February 2024 and the law enforcement disruptions of LockBit and AlphVM in late 2023 and early 2024. Both events redistributed affiliates into newer, less constrained groups that actively selected healthcare as a target category. The sector didn't inherit this ranking. It was pushed into it by structural changes that risk teams need to understand and plan around.

RSI Detected Change Healthcare's Vulnerability 7 Months Before the February 2024 Attack Occurred

The Ransomware Susceptibility Index® (RSI™) recorded three distinct upward shifts in Change Healthcare's risk profile between mid-2023 and the attack date. Each shift corresponded to an observable change in the organization's external-facing technical posture. Each represented a remediation window. None produced a response. 

Organizations with RSI scores between 0.6 and 1.0 are 27x more likely to experience a ransomware attack than those scoring below 0.2. The Change Healthcare case is not an argument that the attack was inevitable. It's the clearest available evidence that early warning signals existed, were not acted on, and that the outcome was therefore not random.

Affiliate-Driven Target Selection Means Healthcare's Exposure Is No Longer Governed by Group Ethics

The most consequential structural change documented in this report is the shift from centralized ransomware group control to affiliate-driven target selection. Ransomware affiliates are independent operators who carry out attacks in exchange for a share of the ransom. Historically, established groups enforced codes of conduct that placed healthcare, emergency services, and critical infrastructure in a limited or off-limits category. That constraint collapsed following the Change Healthcare incident. Affiliates now evaluate targets independently, and their criteria have nothing to do with sector ethics. They assess:

  • Technical vulnerability (unpatched systems, exposed credentials, weak application configurations)
  • Industry profile (sectors with high urgency to restore services and limited downtime tolerance)
  • Likelihood to pay (organizations with operational pressure and demonstrated willingness to settle quickly)

Healthcare scores at or near the top on all three. Small practices account for 25% of healthcare ransomware victims, which confirms that size is not the filter. Exploitability is.

Dark Unicorn Ransomware Groups Now Lead Attacks on Healthcare With No Sector Restrictions

The groups most actively targeting healthcare in 2024 and 2025 represent a new category this report identifies as "Dark Unicorns." These are ransomware operations with valuations above $1 billion that function with the organizational structure of a legitimate enterprise but without any of the ethical limits that previously restrained large-scale ransomware activity against healthcare. RansomHub, Hunters, Medusa, and NightSpire are the primary examples. These groups rose to prominence by absorbing affiliates displaced from LockBit and AlphVM, offering payout splits as high as 90% to affiliates to attract experienced operators. Unlike their predecessors, they do not maintain sector exclusions. Healthcare is not off-limits. It is actively targeted. 

HHS Breach Disclosures More Than Doubled From 2023 to 2024 Across Every Healthcare Breach Category

Data from the HHS Office for Civil Rights Breach Portal provides the regulatory evidence of what the attack volume increase looks like in practice. Healthcare breach disclosures rose more than 100% from 2023 to 2024 across all breach categories. Business associate incidents, which represent third-party vendor breaches with downstream impact on healthcare organizations, increased alongside direct breach disclosures. Ransomware-attributed disclosures grew at a higher rate than non-ransomware categories. Improved reporting transparency accounts for some of the increase. The underlying incident volume accounts for the rest. The sector's supply chain remains the most concentrated exposure, with healthcare-focused vendors frequently serving multiple organizations simultaneously from a shared attack surface.

Healthcare Ransomware at a Glance

0%
Rise in healthcare ransomware incidents from 2023 to 2024
0%
Share of healthcare ransomware victims that are small practices
#3
Healthcare's rank among most targeted industries globally (up from #5)
0months
RSI advance warning before the Change Healthcare attack
0x
Higher ransomware likelihood for organizations with RSI above 0.6
0x+
Increase in HHS breach disclosures from 2023 to 2024

How the Ransomware Ecosystem Restructured Itself and Why Healthcare Became the Primary Casualty

Change Healthcare Exposed the Fault Line Inside the Ransomware-as-a-Service Model

The February 2024 attack on Change Healthcare did more than disrupt healthcare operations across the United States. It revealed a structural weakness inside the ransomware-as-a-service model that affiliates had been watching build for years. When a ransom payment to the BlackCat/AlphVM affiliate who carried out the attack was withheld by the core group, it triggered a rapid reassessment across the affiliate community. If groups could cut affiliates out of payouts, affiliates had no reason to accept the targeting restrictions those groups imposed. The implications for threat actor monitoring were immediate. Groups that had previously avoided healthcare revised their posture. New groups formed with no inherited constraints. The Change Healthcare attack is the single event that most directly explains why healthcare's ransomware targeting rate surged in 2024. Read our detailed breakdown in how the Change Healthcare breach reshaped TPRM priorities.

Dismantling LockBit and AlphVM Produced a Dangerous Ecosystem

The dismantling of LockBit 3.0 in December 2023 and the disruption of AlphVM/BlackCat in early 2024 removed two of the most dominant ransomware groups from active operation. The short-term effect was a measurable reduction in attacks from both groups. The longer-term effect was the redistribution of an experienced, motivated affiliate pool into newer groups with fewer restrictions and more aggressive recruitment terms. RansomHub launched with a 90% affiliate payout model and rapidly absorbed displaced operators from both dismantled groups. The resulting ecosystem is more fragmented, more competitive among groups for affiliate talent, and less constrained in target selection than the one law enforcement disrupted. For a detailed account of how the LockBit takedown played out, see the law enforcement operation that dismantled LockBit.

Affiliate Transitions Between Groups Mean Healthcare Threat Intelligence Has a Structural Lag Problem

One of the most operationally significant findings in this report's ecosystem analysis is how consistently affiliate skills, techniques, and target preferences transfer between groups after a disruption. When a named group is taken down, its affiliates don't stop operating. They evaluate which successor group offers the best payout structure and operational support, then resume activity under a new banner. The threat to healthcare doesn't reset when a group is dismantled. It migrates. 

Supply chain cyber risk management programs and threat intelligence functions built around tracking named groups as stable entities will always lag the actual threat level. The affiliate layer, not the group brand, is where healthcare targeting decisions are made. Understanding which vendors in your ecosystem are currently flagged in active affiliate campaigns is a materially different intelligence problem than knowing which named group is active this quarter.

Ransomware Attack Patterns That Make Healthcare a Persistent High-Priority Target

OSINT Discovery Determines Which Healthcare Targets Get Attacked

Ransomware groups and their affiliates don't begin with a target list. They begin with a discovery process. Before any organization is selected for an attack, it passes through an OSINT-based technical screening that identifies publicly observable vulnerabilities. Organizations that appear in that screening with unpatched systems, exposed credentials, or weak application security configurations move forward in the targeting process. Those that don't, don't. 

The practical implication is that an organization can reduce its probability of selection by reducing its observable attack surface. Continuous monitoring of external-facing technical posture is the mechanism by which healthcare organizations can assess what attackers see when they run that screen. It's not a passive monitoring function. It's an active defense input. See also: the risk factors that make organizations prime ransomware targets.

One-Time Non-Negotiable Ransom Demands Have Replaced the Negotiation Window Healthcare Relied On

The shift from negotiated ransom settlements to direct, non-negotiable demands is one of the most consequential tactical changes for healthcare incident response planning documented in this report. Established ransomware groups historically built negotiation into the ransom process, giving victim organizations time to assess their options, engage legal and law enforcement counsel, and potentially reduce the demand amount. 

Newer groups targeting healthcare with high-volume, lower-overhead attack models have removed that window. Demands are issued with compressed payment timelines. The structural pressure on healthcare is acute: patient care operations cannot pause, backup restoration takes time, and regulatory notification timelines begin running regardless of whether the ransom decision has been made. Healthcare organizations planning incident response based on historical negotiation assumptions are operating on a model that no longer reflects how most active attackers behave.

The Healthcare Vendor Ecosystem Creates a Shared Attack Surface Across Dozens of Organizations

The risk to healthcare organizations from their vendor ecosystem isn't theoretical. It's documented in the HHS breach data, visible in the affiliate targeting patterns, and demonstrated at scale by the Change Healthcare incident itself. The vendors serving healthcare operations share technical infrastructure, credentials, and data access across multiple healthcare organizations simultaneously. A ransomware group or affiliate that compromises a shared vendor doesn't gain access to one organization. It gains a position inside the supply chains of every healthcare organization that vendor serves. The specific vendor categories that create the highest shared exposure risk include:

  • Electronic health record (EHR) software providers serving multiple health systems
  • Medical billing and revenue cycle management services
  • Clinical data exchange and interoperability platforms
  • Medical device manufacturers with remote access or telemetry capabilities

Third-party risk management programs that assess vendors through annual questionnaires rather than continuous external monitoring are blind to the real-time changes in vendor posture that precede most ransomware events. 

For background on this problem in healthcare specifically, see HIPAA obligations for healthcare third-party vendors and why ransomware groups now prioritize healthcare targets.

U.S. Healthcare Organizations Face the Highest Global Concentration of Ransomware Targeting

The United States accounts for the largest share of confirmed healthcare ransomware victims globally by a significant margin. The concentration reflects both the density of high-value targets and the digital maturity of U.S. healthcare infrastructure, which creates a larger exploitable attack surface than less digitized healthcare systems in other geographies. Two revenue segments dominate the victim profile:

  • Large enterprises (revenue above $100 million), which represent high-value ransom targets
  • Small to mid-sized organizations (revenue below $20 million), which represent low-resistance targets with operational urgency

The targeting data is clear on one point: revenue does not determine ransomware exposure. Technical posture and operational urgency determine whether an organization moves from the discovery phase to the active attack phase. Geopolitical monitoring of ransomware group activity provides advance signal on which regions and sectors are being elevated in current affiliate targeting queues, giving healthcare organizations a forward-looking input that breach data alone cannot provide.

Four Defenses That Move Healthcare Organizations Off the Ransomware Radar in 2025

Monitor RSI Continuously So Your Team Can Act During the Window Before an Attack

The Change Healthcare RSI timeline is the clearest argument this report makes for continuous over point-in-time monitoring. Three upward shifts in RSI score, each corresponding to a remediable technical change, appeared between mid-2023 and the February 2024 attack. Each represented a window. The Ransomware Susceptibility Index® (RSI™) tracks 20 risk categories that directly influence ransomware targeting probability, including:

  • Patch management posture and unpatched critical CVE exposure
  • Credential exposure from stealer logs and dark web sources
  • Application security configuration and public-facing vulnerabilities
  • Network-level signals that appear in OSINT-based attacker discovery tools

An upward RSI shift doesn't confirm an imminent attack. It signals that your organization has moved toward the profile that ransomware affiliates screen for when building target lists. Acting on those shifts before selection occurs is what the seven-month Change Healthcare window made possible. Organizations without continuous RSI monitoring don't have access to that window.

Map Every Healthcare Vendor's RSI and Treat High-Scoring Vendors as Active Exposure Events

Your organization's RSI score reflects your own technical posture. It tells you nothing about the vendors whose systems connect to your patient data, clinical workflows, or billing infrastructure. Each vendor has its own RSI profile. A vendor scoring above 0.6 that manages EHR integrations, processes insurance claims, or operates networked medical devices inside your environment represents a third-party ransomware exposure that doesn't appear anywhere in your own security metrics. Vendor risk monitoring applied to the full healthcare vendor ecosystem is the second monitoring layer that the Change Healthcare case study confirms is not optional. 

For a practical perspective on vendor-level risk in healthcare, see ransomware exposure in small business vendor relationships and why smaller vendors in your ecosystem carry outsized risk.

Map Threat Actor Activity at the Affiliate Level

Healthcare threat intelligence built around named ransomware group tracking will consistently lag the actual threat environment by weeks or months. The affiliate transition data in this report documents exactly how this lag occurs. When LockBit was dismantled, its affiliates didn't stop operating. They moved to RansomHub, Hunters, Medusa, and other successor groups, bringing their techniques and target preferences with them. The named group changed. The threat to healthcare didn't. 

The Adversary Susceptibility Index™ (ASI™) tracks threat actor activity at the affiliate level, identifying which groups are actively running campaigns against healthcare infrastructure and which vendors in your monitored ecosystem are currently flagged with active FocusTags® tied to healthcare-relevant attack activity. That intelligence layer doesn't exist in a quarterly threat report. It requires real-time signal from continuous monitoring infrastructure.

Build Vendor Breach Coordination Into Incident Response Before a Vendor Breach Triggers It

Most healthcare incident response plans are designed around a direct breach scenario: the compromised organization is also the point of entry. The vendor breach scenario documented repeatedly in this report works differently. Your organization is affected. The compromised entity is a vendor you rely on. Your regulatory disclosure obligations, patient notification requirements, and operational recovery timelines begin running regardless. Most incident response plans are not designed for that coordination model. The Bridge™ provides the secure, structured communication layer between healthcare organizations and their vendors that makes coordinated breach response tractable rather than reactive. 

The organizations that managed the Change Healthcare fallout most effectively had vendor communication protocols in place before the event. Those that didn't found themselves coordinating under pressure with vendors who had no established channel for sharing incident details. 

See how vendor breach coordination is evolving across industries for context on what leading programs are building toward.

How Black Kite Built the 2025 Healthcare Ransomware Report

All Ransomware Incidents Verified Through Confirmed Encryption, Exfiltration, and Attribution

Every ransomware incident in this report reflects a confirmed victim case where encryption, data exfiltration, and attribution to a named group were independently verified. The Black Kite Research Group™ curated data across surface, deep, and dark web sources, cross-referencing published breach disclosures with direct threat intelligence from ransomware group infrastructure monitoring. Incidents based on unverified claims, single-source reporting, or unattributed attacks were excluded from the dataset. 

The incident counts in this report represent a conservative lower bound of actual healthcare ransomware activity. Many incidents involving smaller organizations are resolved without public disclosure and are not captured by any available data source.

HHS OCR Breach Portal Cross-Referenced Against Black Kite Research Group™ Tracking to Surface Disclosure Timing Gaps

The HHS Office for Civil Rights Breach Portal records healthcare data breaches affecting 500 or more individuals. Black Kite Research Group™ analysts cross-referenced portal data against the ransomware victim tracking dataset to identify ransomware-attributed disclosures, business associate incidents, and the gap between attack date and public disclosure date. That gap analysis is a key methodological contribution of this report. It demonstrates that the regulatory disclosure timeline in many cases significantly trails the actual attack date, which has material implications for third-party risk programs that rely on vendor self-disclosure as a primary breach detection mechanism. The 2023-to-2024 comparison provides the evidentiary basis for the documented doubling of breach disclosures across the reporting period.

RSI Trend Data for Change Healthcare Captured Continuously From March 2023 Through January 2024

The Change Healthcare RSI analysis used historical data captured by Black Kite's continuous monitoring infrastructure across a 10-month window preceding the attack. RSI scores are recalculated continuously across 20 risk categories as new signals emerge from network-level scans, credential exposure databases, and vulnerability intelligence feeds. The three upward shifts documented in the report correspond to specific, observable changes in Change Healthcare's technical posture. The analysis is replicable for any organization within Black Kite's monitoring coverage and establishes the methodological basis for the report's early warning system argument.

Affiliate Transition Map Constructed From 24 Months of Dark Web and Victim Announcement Tracking

The affiliate transition analysis in this report was built from the Black Kite Research Group™'s tracking of ransomware group victim announcements, dark web forum activity, and affiliate recruitment communications from Q1 2023 through Q4 2024. Affiliate movement between groups was identified through technique signature overlap, target pattern analysis, and direct intelligence from forums where affiliates discuss group selection. The resulting transition map documents how affiliate talent, skills, and targeting preferences flow between groups after disruptions, forming the evidentiary basis for the report's finding that named group takedowns do not neutralize the healthcare threat. They redistribute it.

Related Resources