Healthcare Is Hit by a Cyberattack Every 10 Hours — and Attackers Are Walking Through Doors Left Open, Securin Finds
Cyber Security / Foundational Security | 4 min read
Healthcare organisations are being hit by cyberattacks at a rate of approximately one every 10 hours — and the attacks are succeeding not through novel or sophisticated techniques, but through vulnerabilities that are already known and fixable. That is the central finding of the Securin Healthcare Threat Intelligence Report, which analysed 592 incidents conducted by 94 ransomware groups between January 2025 and February 2026. The report was published by Securin (Milpitas, California and Albuquerque, New Mexico), an AI-driven cybersecurity company that helps organisations identify, validate, and eliminate real-world cyber risk before it becomes a breach. Ransom payment rates in healthcare range from 68% to 72% — making the sector one of the most reliable and profitable targets for cybercriminals anywhere. The problem is compounding for a straightforward reason: attackers are succeeding, and once inside healthcare systems, the disruption is so severe that organisations are often forced into costly decisions.
"Ransomware in healthcare has become a repeatable business model. Attackers are walking through doors that were left open — and getting paid for it. Once they're inside, the disruption is so severe that organisations are often forced into costly decisions — in many cases tied to issues that could have been addressed earlier."
— Dr. Srinivas Mukkamala, CEO, Securin
Low Entry Costs, High Payment Rates — The Economics Driving the Cycle
The report reveals that initial access to healthcare systems can be purchased by attackers for as little as $2,000 to $50,000 — a remarkably low barrier to entry given the value of the disruption that access enables. Once inside, attackers can encrypt critical systems, lock medical records, and paralyse essential services, demanding ransoms that vastly exceed the access cost. With payment rates between 68% and 72%, the financial logic for attackers is clear: healthcare is uniquely vulnerable to operational disruption because the cost of downtime is measured not just in money but in patient safety and continuity of care. Certain ransomware groups have scaled their operations specifically by exploiting the same known vulnerability across multiple healthcare organisations simultaneously — including Qilin, Incransom, and Cl0p. These groups demonstrate the repeatable, industrialised nature of healthcare ransomware: one exploitable weakness identified, deployed against dozens of targets before patches are applied. The pattern is self-reinforcing: each successful payment validates the model, funding further attacks and lowering the threshold for new entrants to the ransomware ecosystem.
Known Vulnerabilities, Fixable Gaps — The Core of the Problem
The most significant finding of the report is not the scale of attacks but their nature: attackers are not exploiting zero-days or advanced persistent threats requiring sophisticated resources. They are exploiting known, fixable vulnerabilities — weaknesses that have been documented, patched, and publicly disclosed, but that remain unaddressed in healthcare environments. This reflects structural challenges in healthcare cybersecurity: legacy systems that are difficult to patch without disrupting clinical operations, under-resourced IT and security teams, insufficient staff training, and a tendency to prioritise operational continuity over security remediation. The result is that healthcare organisations remain exposed to vulnerabilities that defenders in other sectors would have closed. Faced with the pressures of an active attack, many organisations make difficult decisions to restore operations quickly — paying ransoms rather than bearing the cost of extended downtime — which reinforces the very cycle that makes healthcare such a reliable target. Securin's full Healthcare Threat Intelligence Report is available at securin.io.
Key Takeaways
- • Securin (Milpitas, California and Albuquerque, New Mexico; AI-driven cybersecurity; CEO Dr. Srinivas Mukkamala) has published the Healthcare Threat Intelligence Report — analysing 592 incidents conducted by 94 ransomware groups between January 2025 and February 2026. Core finding: healthcare organisations are hit by cyberattacks at a rate of approximately one every 10 hours. Attacks are succeeding using known, fixable vulnerabilities — not novel or sophisticated techniques.
- • The economics: initial access to healthcare systems is purchased for as little as $2,000 to $50,000 — lowering the barrier to entry dramatically. Ransom payment rates range from 68% to 72% — making healthcare one of the most reliable and profitable targets for cybercriminals. Once inside, the disruption is so severe that organisations are often forced into costly decisions, typically choosing to pay rather than bear extended downtime impacting patient care and operations.
- • Named ransomware groups scaling through known vulnerabilities: Qilin, Incransom, and Cl0p have scaled attacks by exploiting the same vulnerability across multiple healthcare organisations simultaneously — demonstrating the industrialised, repeatable nature of healthcare ransomware. One exploitable known weakness identified, deployed at scale against multiple targets before patches are applied. The model is self-reinforcing: each successful payment validates the approach and funds further attacks.
- • Why known vulnerabilities remain exploitable in healthcare: legacy systems difficult to patch without disrupting clinical operations; under-resourced IT and security teams; insufficient staff training; tendency to prioritise operational continuity over security remediation. The result is that healthcare organisations remain exposed to vulnerabilities that defenders in other sectors would have already closed — creating the structural gap that ransomware groups are systematically exploiting.
- • The self-reinforcing cycle: attackers succeed → organisations pay to restore operations → payment rates (68–72%) confirm profitability → further attacks are funded → access costs remain low ($2,000–$50,000) → more groups enter → attack frequency increases → one attack every 10 hours. Breaking this cycle requires addressing known vulnerabilities before attackers exploit them — the core capability Securin's AI-driven cybersecurity platform is built to provide. Full report available at securin.io.
