Healthcare Ransomware Attacks Shift: Businesses Up 35% While Hospitals Hold Flat

Clinic administrator working at a laptop in a bright medical office

Ransomware crews hit healthcare organizations 410 times in the first half of 2026, and the hospitals were not the story. Researchers at Comparitech, who track ransomware claims and confirmed breaches across sectors, counted a rise of just over 3 percent in attacks on hospitals, clinics, and other care providers. Healthcare ransomware attacks on the businesses around those providers, the billing firms, manufacturers, and drug wholesalers, rose almost 35 percent.

Where healthcare ransomware attacks landed in H1 2026

The tally splits 410 attacks into 247 against direct care providers and 163 against healthcare businesses. Inside that business layer, the growth is lopsided. Medical retailers and drug wholesalers absorbed a 67 percent jump. Manufacturers rose 36 percent, and healthcare tech firms 12 percent. The sector now averages 2.3 attacks per day, up 14 percent overall from the second half of 2025.

The gang names change with the target. Qilin, the most prolific strain against providers, logged 41 claims and 8 confirmed attacks. The Gentlemen appeared heavily on both sides of the line, while DragonForce led claims against healthcare businesses. Most of these attacks are still unconfirmed: only 77 of the 410 have been verified so far, with 424,740 records known breached at providers and another 154,825 at businesses.

Country by country, the picture shifts. The United States took 225 of the 410 attacks, yet US provider attacks actually fell 7 percent while US business attacks rose 11 percent. India’s provider attacks grew eightfold from a small base, and Canada’s rose 83 percent.

Why the business layer is where the pressure moved

Read the ransom table before the headline number. Median demands came in at $310,000 against providers and $300,000 against businesses. Attackers now price a billing platform’s data within 3 percent of a hospital’s. That is the finding that should change behavior: the criminals now price the two the same, while most third-party risk programs still don’t.

The Unimed case shows the working model. The German billing service provider was attacked in April, the encryption attempt failed, and around 135,000 patients still had to be notified because the data left anyway. The criminals did not need the encryption to work; taking the data was already the business. Stolen healthcare records feed a resale market that actively seeks breach-sourced data. That market is why a wholesaler with thin margins and a flat security budget makes a better target than a hospital with a 24/7 security operation.

The slow reporting makes it worse. Nine of the ten biggest healthcare ransomware attacks of the half happened in the first quarter, and some victims are still sending notification letters today. No payment was officially confirmed all half, though Unimed is rumored to have paid for deletion, and six victims stated outright that they refused. NetRunner’s $100 million demand on Japan’s Nippon Medical School Musashi Kosugi Hospital went unpaid; the University of Mississippi Medical Center canceled appointments for nearly two weeks while it contained a Medusa attack.

How to act on the H1 2026 numbers

Re-tier the healthcare businesses in the vendor register. The 67 percent surge landed on exactly the companies most programs file as low-criticality IT vendors: billers, device retailers, drug wholesalers. If a wholesaler outage would stall your pharmacy inside a week, that vendor’s security posture deserves tier-1 scrutiny, and this report is the data to justify the re-tier.

Ask suppliers the exfiltration question, not the backup question. Unimed lost 135,000 patient records without a single system getting encrypted, so a good backup story proves nothing about whether the data got out. Ask billing and supply partners what watches their outbound traffic, and treat an answer built entirely on backups as a red flag.

Build a detection trigger that does not wait for the letter. With 333 of 410 attacks unconfirmed and quarter-old incidents still surfacing, formal notification will reach you months after the criminals did. Monitor leak-site claims for the names of your suppliers, or buy intelligence that does, and rehearse the day one of those names appears.

Nothing in the H1 healthcare ransomware data lets hospitals relax. The sharper reading is that attackers found equal money and less resistance one step upstream, in companies that rarely make breach headlines. If the third-party register still treats billers and wholesalers as background IT suppliers, that judgment is now six months stale, because the people setting ransom prices have already revised theirs.

Join our LinkedIn group Information Security Community!

Holger Schulze
Holger Schulze is the founder and publisher of Cybersecurity Insiders, an independent cybersecurity research and media company. He writes about how AI is reshaping cybersecurity, where attackers are moving faster than defenses, and what security leaders can do about it. His work draws on original research and real-world incidents, translating both into practical guidance for security teams. Holger moderates the Information Security Community on LinkedIn, one of the largest professional networks in cybersecurity. Connect at linkedin.com/in/holger-schulze

No posts to display