Healthcare was targeted by 154 of 200 ransomware groups analyzed by Anomali, representing 77% of the ransomware groups included in the analysis.
Anomali analyzed ransomware targeting across eight United States industry sectors: technology, manufacturing, healthcare, government public services, financial services, construction, energy, and education. The analysis identified targeting by 200 distinct ransomware entities.
All eight sectors had an observed targeting presence above 50%. Technology was targeted by 172 of the 200 ransomware entities, representing 86%. Manufacturing was targeted by 166 entities, representing 83%. Healthcare ranked third in the analysis, with 154 entities targeting the sector, representing 77%.
The analysis was published in Anomali’s US Ransomware Industry Targeting Report.
Healthcare Ransomware Exposure
The analysis identifies healthcare as an attractive target for ransomware groups because healthcare organizations combine patient care, protected health information (PHI), insurance, payments, and clinical operations. These functions provide multiple points of leverage for extortion.
Healthcare organizations under HIPAA depend on continued access to patient data. An attack that prevents access to that information can create a safety risk. Ransomware attacks can also pressure healthcare organizations to restore operations quickly. The source states that this pressure can increase the likelihood that a ransom will be paid.
Healthcare organizations also operate with a broad attack surface that includes legacy systems and devices that cannot be patched. These conditions are factors that can make attacks easier than in some other sectors.
Common Ransomware Entry Points
Unpatched VPNs, firewalls, edge devices, and other internet-facing applications are common entry points into healthcare environments. Anomali states that these internet-facing systems are likely to remain high-value entry points for ransomware groups. The report recommends closing internet-facing exposure before attackers can exploit it and identifies VPNs, edge devices, firewalls, backup platforms, remote monitoring and management tools, and externally reachable software programs as areas for attention.
Identity and Access Controls
Anomali recommends considering identity as the main ransomware boundary. Its recommendations include phishing-resistant multifactor authentication for administrators, single sign-on, remote access, VPNs, and privileged service accounts.
The source also recommends removing exposed Remote Desktop Protocol, reviewing accounts for stale access, and continuously checking credential exposure and anomalous sign-ins.
Recovery and Detection Measures
File encryption can disrupt healthcare operations, hence, offline backups for critical systems and data are recommended, and restoration protocols must be tested under ransomware conditions.
Anomali also reported evidence that endpoint detection and response evasion has become a common part of ransomware affiliate activity. The company predicts greater use of tools designed to terminate endpoint detection and response protections over the forthcoming year.
Additional recommendations include preserving centralized logs, enabling endpoint detection and response tamper protections, and checking PowerShell, remote monitoring and management activity, and data exfiltration behavior.
Healthcare Operations and Ransomware Activity
Patrick Holt, head of product at Anomali, stated that ransomware creates a difficult threat for healthcare organizations because patient care cannot simply stop while systems are restored. He also stated that ransomware groups are broadening their targeting and reusing tactics across industries.
The analysis identifies healthcare as one of eight sectors targeted by the 200 ransomware entities examined by Anomali. Within that analysis, 154 entities targeted healthcare, producing an observed targeting presence of 77%.
Image credit: pira555 227001630 Adobestock









