Site navigation

67% of Healthcare Organisations Hit by Ransomware In the Past Year

Tom Quinn

,

healthcare ransomware attacks
95% of healthcare organisations say that cybercriminals attempted to compromise data backups during an attack,  and that organisations whose backups were compromised are more than twice as likely to pay a ransom.

Fresh research from cybersecurity firm Sophos has found that two-thirds (67%) of healthcare organisations were impacted by ransomware attacks in the past year, up from 60% in 2023. 

Sophos’ report, The State of Ransomware in Healthcare 2024, contains insight from IT and cybersecurity leaders within 402 healthcare organisations across 14 countries, and found that, on average, 58% of computers in healthcare organisations have been affected by a ransomware attack.

According to this year’s data, exploited vulnerabilities and compromised credentials (both at 34%) were the most common entry methods for ransomware attacks in the healthcare sector, followed by malicious emails (19%), phishing (9%), and brute force attacks (4%).

Once ransomware attackers have gained access to a system, things go from bad to a lot worse, with 95% of healthcare organisations saying that cybercriminals also attempted to compromise their backups during the attack.

According to Sophos, attackers are using the tactic to put more pressure on firms, with the research showing that organisations whose backups were compromised were more than twice as likely to pay the ransom to recover encrypted data (63% vs. 27%).

Adversaries don’t just encrypt data; they also steal it. Healthcare respondents reported that in 22% of incidents where data was encrypted, data was also stolen, a considerable decrease from the 37% reported by healthcare respondents last year. 

Meanwhile, the mean cost of recovery following a ransomware attack has gone up, hitting $2.57 million (£1.92 million) in 2024, up from $2.2 million (£1.64 million) in 2023 and double the 2021 cost.

The report also makes it clear that it isn’t just a matter of losing money, it’s also about losing time. Sophos’ research shows that the time taken to recover from a ransomware attack has steadily increased in the healthcare sector, with only 22% of ransomware victims fully recovering in a week or less in 2024, a considerable drop from the 47% in 2023 and 54% in 2022.

Notably, 37% took more than a month to recover, a sharp increase from 28% in 2023.


Recommended reading


John Shier, field CTO at Sophos, said: “While we’ve seen the rate of ransomware attacks reach a kind of “homeostasis” or even declining across industries, attacks against healthcare organisations continue to intensify, both in number and scope. 

“To combat these determined adversaries, healthcare organisations must adopt a more proactive, human-led approach to threat detection and response, combining advanced technology with continuous monitoring to stay ahead of attackers.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data