Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-24 · updated: 2026-09-24 · tags: [incident, healthcare, ransomware, phishing] · confidence: high · severity: high · affected_sectors: [healthcare] · au_impact: true

Anomali's US Ransomware Industry Targeting Report analysed targeting by 200 distinct ransomware entities across eight sectors and found more than 50% observed presence in every one — technology first with 172 groups (86%), manufacturing with 166 (83%) and healthcare third with 154 (77%). The finding is not that healthcare is uniquely targeted but that it is targeted near-universally, which changes the defensive question from "will we be a target" to "which of 154 groups will arrive first". Anomali's explanation is consistent with the incident record: healthcare combines patient care, protected health information, insurance, payments and clinical operations into one extortion surface, cannot tolerate the loss of access to patient data because that is a safety risk, faces acute pressure to recover quickly, and carries legacy systems and unpatched devices that cannot be remediated on a modern cadence. The entry points named are the familiar internet-facing set — unpatched VPNs, firewalls, edge devices, backup platforms, remote monitoring and management tooling and externally reachable applications — and the recommended controls are identity-led: phishing-resistant MFA for remote access, administrators, SSO, VPN and privileged service accounts, removal of exposed RDP, stale-account review and continuous monitoring for credential exposure.

Attribute Detail
Sector Healthcare
Date 2026-09-24
Source HIPAA Journal
Reliability Tier 2