VYPR
breachPublished Jul 24, 2026· 1 source

Ransomware Gangs Broaden Healthcare Attack Surface in EMEA

Ransomware groups are increasingly targeting the entire healthcare supply chain in the EMEA region, extending beyond hospitals to telemedicine providers, diagnostic labs, and pharmacies.

Ransomware attacks on hospitals frequently capture headlines, but the broader healthcare ecosystem is facing a growing wave of disruption that can be equally devastating. Research analyzing ransomware leak site activity between 2024 and 2026 reveals a significant trend: threat actors are systematically targeting not just traditional healthcare facilities, but also the interconnected network of telemedicine providers, diagnostic laboratories, pharmacies, and other essential service providers within the EMEA region.

This expanded focus broadens the attack surface considerably, creating new avenues for attackers to compromise patient data and disrupt care. The analysis by Flare researcher Assaf Morag identified 14 distinct threat actor groups, including prominent names like Qilin, LockBit 3.0, RansomHub, and DragonForce, actively pursuing these diverse healthcare-related targets. The dataset encompasses a wide array of organizations, from hospitals and clinics to rehabilitation services, healthcare software vendors, staffing agencies, medical equipment suppliers, and public health agencies.

Some entities are targeted directly due to their critical role in patient safety. Others serve as stepping stones, with attackers aiming to leverage access to these smaller entities to gain entry into larger, more fortified targets like hospitals that rely on them for patient records, critical equipment, or integrated IT systems. Notable incidents highlighted include attacks on the American Hospital Dubai, Spire Healthcare, NRS Healthcare, and Genie Healthcare, with substantial data exfiltration claims.

A smaller group known as Kazu, which emerged in mid-2025, initially focused on government and public sector victims. However, Flare observed Kazu shifting its attention to the healthcare sector, with attacks on an Italian telemedicine provider and subsequent postings indicating a growing interest in healthcare organizations and related data, extending even to Latin America.

The financial implications of these attacks are staggering. The infamous February 2024 attack on Change Healthcare, a major US healthcare payment processor, resulted in the theft of over six terabytes of data, disrupted an estimated 40% of US medical claims processing, and incurred total damages estimated at $2.87 billion, despite a $22 million ransom payment. In the EU, the Coalition for Health, Ethics & Society reported 289 cybersecurity incidents in the healthcare sector in 2024, with average major incidents costing around €300,000 and cumulative annual impacts in the billions.

Compounding these issues are the persistent challenges within European healthcare institutions, including reliance on legacy technologies, fragmented IT environments that hinder patching and recovery, delayed implementation of security regulations, workforce shortages, and the rapid expansion of interconnected medical devices. These structural vulnerabilities make them prime targets for ransomware operations.

Experts argue that ransomware attacks against healthcare facilities have evolved beyond a mere criminal problem into an operational and geopolitical threat to European resilience. The significant costs associated with these attacks are often driven more by operational disruption and recovery efforts than by the ransom payments themselves, underscoring the critical need for enhanced cybersecurity measures across the entire healthcare supply chain.

Synthesized by Vypr AI