In the late spring of 2026, the FBI's co-deputy director delivered a message to hospital leaders that was equal parts warning and indictment of the status quo. The attacks that are shutting down emergency departments, diverting ambulances, and forcing nurses back to paper records are, for the criminal groups behind them, completely ordinary. "We're at a point where they're attacking a hospital system, and it's just normal routine transactions for these groups," said FBI co-deputy director Paul Abbate. "For the hospital on the receiving end, it's anything but."

 

What 2025 actually looked like

Healthcare finished 2025 as the most targeted sector in the United States for cybercrime, a position it has held for years. According to the FBI's 2025 Internet Crime Report, the healthcare and public health sector recorded 642 cyber incidents, 460 ransomware attacks, and 182 data breaches, more than any other of the 16 critical infrastructure sectors tracked. Financial services came second with 447. Ransomware losses reported to IC3 across all sectors reached $32.3 million in 2025, a 259% increase from the prior year, though the FBI acknowledges these figures exclude business disruption, equipment damage, and third-party remediation costs, meaning the real figure is substantially higher.

DaVita, one of the largest kidney dialysis providers in the US, was hit by a ransomware attack in April 2025. The Interlock group claimed responsibility, later publishing data it said it had exfiltrated 1.5 terabytes of patient and operational information. The breach officially reached 2.69 million individuals. DaVita's billing and revenue collection were disrupted, patient census was affected, and the company expected the impact to weigh on treatment revenue for the full year. In March, Yale New Haven Health System reported a breach affecting 5.5 million patients, the largest in its history, following unauthorized access to a network server.

According to Paubox's 2026 Healthcare Email Security Report, 170 email-related healthcare breaches occurred in 2025, affecting more than 2.5 million individuals, with phishing as the dominant entry point. Ransomware attacks on healthcare have surged 264% since 2018, according to HHS OCR data cited in Paubox's 2025 Healthcare Email Security Report.

Read more: What is ransomware? | What is phishing? | What is Ransomware-as-a-Service?

 

Why information sharing isn't working

The FBI's plea to hospitals to share threat intelligence is not new. The Health Information Sharing and Analysis Center (Health-ISAC) has operated as a collective defense platform for years. Joint advisories from CISA, HHS, and the FBI regularly document active ransomware groups and their tactics. The Interlock group, which hit DaVita and is suspected in the Kettering Health attack, was the subject of a July 2025 joint advisory from the FBI, HHS, CISA, and MS-ISAC that specifically warned about drive-by download attacks targeting healthcare infrastructure.

DaVita was breached anyway, Kettering Health was breached anyway; organizations that receive the advisories, read them, and presumably take some action are still getting hit at a rate that makes healthcare the most targeted sector in the country.

Several structural problems explain why hospitals face genuine legal ambiguity around sharing breach information; however, HIPAA's liability framework discourages disclosure of incident details that could expose an organization to regulatory or legal risk. IT and security staff in many healthcare environments are too thin to act on intelligence even when they receive it. And the ransomware groups' advisories document is adaptive: Interlock modified its techniques between its first documented attacks and subsequent campaigns, meaning intelligence about past behavior has a limited shelf life against groups that learn from law enforcement attention.

John Riggi, AHA national advisor for cybersecurity and risk, was direct in responding to the FBI's 2025 report, stating, "The vast majority are perpetrated by foreign ransomware gangs, primarily Russian-speaking groups, which specifically target healthcare, hoping for a big payout. They know these attacks cause disruptions and delays to digitally dependent healthcare delivery, posing a risk to patient and community safety, thereby increasing the exigency and pressure for a potentially large ransom payment."

Read also: What is threat intelligence?

 

The push for terrorism designations

The FBI deputy director's public plea coincided with separate congressional testimony that went considerably further. Cynthia Kaiser, who served as deputy assistant director of the FBI's cyber division from 2022 to 2025 and now leads research at the Halcyon Ransomware Research Center, testified before the House Homeland Security Committee in April 2026. Her testimony, reported by The Register and Nextgov, called on the State, Justice, and Treasury departments to assess terrorism designations for ransomware actors who knowingly and repeatedly target hospitals. She also urged federal prosecutors to evaluate homicide charges under federal felony murder standards in cases where attacks against healthcare facilities result in documented patient deaths.

"The gap between the severity of these crimes and the consequences that follow needs to be closed," Kaiser told lawmakers.

It is not a fringe position. Studies have established that in-hospital mortality rises during ransomware attacks and that the effects extend to neighboring hospitals absorbing diverted patients. The argument that attacking a hospital is structurally equivalent to an act of violence is one that academic researchers, clinicians, and now former senior law enforcement officials are making with more specificity than before. Whether the legal framework follows is a separate question, but the conversation has shifted from whether ransomware on hospitals causes harm to whether that harm meets the threshold for criminal charges beyond fraud.

 

What attackers are actually doing

The FBI's 2025 IC3 report identified 63 new ransomware variants in 2025, averaging five new families per month. The top variants affecting healthcare were Akira, Qilin, INC Ransom/Lynx/Sinobi, BianLian, and Play. According to the security analysis of 2025 breach trends, the most notable shift in attacker behavior was a move from opportunistic attacks toward highly coordinated, multi-stage operations, with attackers spending more time inside networks before deploying ransomware, expanding the scope of exfiltration, and increasingly targeting backups to eliminate recovery options.

"Attackers are shifting from simply encrypting data to corrupting backups, damaging infrastructure, or compromising clinical systems in ways that prolong downtime. The goal is not just extortion, it's to strike maximum operational impact to increase the likelihood of payment," noted Dave Bailey, vice president of security services at Clearwater, in an analysis cited by Bank Info Security.

Email is where most of it starts. Microsoft Threat Intelligence analysis of 13 hospital systems found that 93% of malicious cyber activity observed was tied to phishing campaigns and ransomware, with most activity originating from email-based threats. According to Paubox's 2025 Healthcare Email Security Report, only 5% of known phishing attacks are reported by employees to security teams, meaning the overwhelming majority of delivery attempts go undetected at the human level. Attackers rely on that gap. The email that delivers initial access through a credential-harvesting page or malicious attachment is the most controllable point in the entire attack chain, and it is the one most consistently left under-defended.

 

What a realistic defense looks like

No healthcare organization can hire its way out of this problem. Rural hospitals with a single IT generalist cannot build a security operations center. Mid-sized systems with stretched margins cannot fund the depth of tooling that financial services organizations maintain. The calculus has to be about where the highest-impact controls sit.

Pre-delivery email filtering is the clearest answer to the most common entry point. Removing phishing messages before they reach clinical staff, who are moving fast and under pressure, eliminates the mechanism through which most ransomware chains begin. According to Paubox's 2026 Healthcare Email Security Report, attacks avoiding native email defenses rose 47% in 2025, and phishing emails increased 17%. Native filtering in Microsoft 365 and Google Workspace is not catching what it needs to catch. Paubox Inbound Email Security uses AI to analyze sender behavior, message intent, and tone, stopping phishing attempts that signature-based systems miss before they reach inboxes.

MFA on remote access systems is still not universal across healthcare, despite years of guidance and a clear lesson from Change Healthcare, where attackers entered through a remote access portal with no MFA in place. That breach compromised 100 million individuals and cost $2.4 billion in response costs. Although the control exists, the implementation remains inconsistent.

Offline backups that have been actually tested, not just created and filed, are the difference between a disruptive incident and a catastrophic one. Attackers now routinely target backup systems specifically to eliminate recovery options. A backup that has never been tested under real conditions is not a recovery plan.

HHS has published voluntary Cybersecurity Performance Goals for healthcare, providing a prioritized baseline for organizations trying to close the most dangerous gaps without unlimited resources. The list is not surprising; it stresses MFA, patching of known vulnerabilities, email security, and tested incident response. The organizations breached in 2025 largely lacked one or more of those basics.

 

FAQs

Why is healthcare the most targeted sector for ransomware?

Patient data is among the highest-value information on the criminal market; healthcare organizations cannot afford extended downtime without risking patient safety, and the sector has historically underinvested in cybersecurity relative to its risk profile. All three factors together make healthcare attractive to financially motivated ransomware groups who know that operational disruption creates pressure to pay quickly.

 

Why doesn't threat intelligence sharing between hospitals stop these attacks?

Sharing works when the intelligence is timely, specific, and actionable, and when recipient organizations have the staff and resources to act on it. Healthcare institutions face legal ambiguity around disclosing incident details, thin IT teams that cannot absorb additional information, and adversaries who adapt quickly. The Interlock group was the subject of a joint federal advisory months before it hit DaVita. The advisory documented its methods. The attack happened anyway.

 

What does the push for terrorism designations mean practically?

If ransomware groups targeting hospitals were designated as terrorist organizations, it would trigger sanctions authority, restrict financial flows that support their operations, and potentially enable prosecution under statutes that carry heavier penalties. The practical effect would depend on whether the groups operate in jurisdictions that cooperate with US law enforcement; most do not, which is why Russian-speaking groups operate with effective impunity.

 

How does email connect to ransomware in healthcare?

Email is the most common initial access vector. Phishing delivers credential harvesting pages and malware payloads that give attackers the foothold they need to conduct network reconnaissance and eventually deploy ransomware. Microsoft Threat Intelligence found that 93% of malicious cyber activity observed across 13 hospital systems originated from email-based threats. Stopping delivery before it reaches clinical staff removes the entry point.

 

What should a small or rural hospital prioritize with limited resources?

Three controls address the most common failure points: MFA on all remote access systems, pre-delivery email filtering that stops phishing before it reaches staff, and offline backups tested against realistic recovery scenarios. These do not require a large security team to implement and maintain, and they address the entry points and recovery failures that define most healthcare ransomware incidents.

Learn more: Paubox Inbound Email Security | Paubox's 2026 Healthcare Email Security Report | Paubox's Top 3 Healthcare Email Attacks in 2025