Utopia Tech
Healthcare3 min read

77% of Ransomware Groups Are Targeting the Healthcare Sector

A new analysis of ransomware activity reveals broad, consistent targeting pressure across the United States. Ransomware activity is not limited to any specific industry, with all sectors attacked to varying degrees. The analysis was conducted by the AI-driven cybersecurity and threat intelligence platform provider Anomali, with the findings published in its US Ransomware Indust

UT

Utopia Tech

September 23, 2026 · 3 min read

Share

A new analysis of ransomware activity reveals broad, consistent targeting pressure across the United States. Ransomware activity is not limited to any specific industry, with all sectors attacked to varying degrees. The analysis was conducted by the AI-driven cybersecurity and threat intelligence platform provider Anomali, with the findings published in its US Ransomware Industry Targeting Report .

Anomali observed ransomware targeting across 8 industry sectors by 200 distinct ransomware entities, with its analysis showing that technology was the most targeted sector, followed by manufacturing and healthcare. Anomali looked at ransomware targeting across eight industry sectors – technology, manufacturing, healthcare, financial services, government public services, construction, education, and energy.

There was in excess of 50% observed targeting presence in all eight sectors, with technology companies targeted by 172 of the 200 ransomware entities (86%), followed by manufacturing with 166 (83%), and healthcare in third place with 154 (77%). The healthcare sector has long been an attractive target for ransomware groups as it is a high-pressure extortion environment combining patient care, protected health information, insurance, payments, and clinical operations, which provides multiple points of leverage for extortion.

The healthcare industry is reliant on continuous access to patient data, and any attack that prevents access creates a significant safety risk. There is pressure on victims to recover rapidly, which increases the likelihood of a ransom being paid. Further, a sprawling attack surface, including legacy systems and devices that cannot be patched, makes attacks easier than in many other sectors.

While there are many potential entry points, the most common are unpatched VPNs, firewalls, edge devices, and other internet-facing applications, and these are likely to remain the most high-value entry points into healthcare environments. Internet-facing exposure should be closed before ransomware groups are able to exploit it, focusing on VPNs, firewalls, edge devices, backup platforms, RMM tools, and externally reachable applications.

Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy Anomali recommends treating identity as the primary ransomware boundary and ensuring that phishing-resistant multifactor authentication is implemented for remote access, administrators, SSO, VPN, and privileged service accounts.

Exposed RDP should be removed, reviews should be conducted to identify stale accounts, and there should be continuous monitoring for credential exposure and anomalous logins. File encryption causes significant disruption to healthcare operations, so a rapid recovery is essential. Offline, immutable backups should be created for all critical systems and data, and restoration procedures should be tested under ransomware conditions.

Anomali has seen evidence that EDR evasion is becoming a common part of the affiliate playbook and predicts increased use of EDR-killing tools by adversaries over the coming year. Anomali recommends enabling EDR tamper protections, preserving centralized logs, and monitoring PowerShell, RMM, and exfiltration behavior, and rehearsing legal, communications, regulatory, and law-enforcement decisions before an extortion deadline.

“Healthcare organizations face an especially difficult ransomware threat because attackers know that patient care cannot simply pause while systems are restored. As ransomware groups broaden their targeting and reuse the same tactics across industries, healthcare leaders need real-time threat intelligence that helps them identify emerging activity earlier, prioritize the risks most likely to affect their environment and respond before an intrusion disrupts patient care,” Patrick Holt, head of product at Anomali, told the HIPAA Journal.

The post 77% of Ransomware Groups Are Targeting the Healthcare Sector appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content