Healthcare Ransomware on the decline in 2025, but why? 

Comparitech researchers have released a study looking at the impact of healthcare ransomware in H1 2025, finding a decline in attacks compared to H1 2024. 

While the healthcare sector hasn’t seen the same influx in attacks as other industries (a recent 2025 H1 report saw a 50 percent increase across the board from 2024), this could be due to several factors.

Ransomware attacks on healthcare companies continue to have devastating consequences. This became only too evident recently when a patient’s death was linked to the June 2024 attack on Synnovis in the UK.

Key findings include:

  • 211 attacks in total – 125 in Q1 and 86 in Q2
  • 68 confirmed attacks – 45 in Q1 and 23 in Q2
  • 143 unconfirmed attacks – 80 in Q1 and 63 in Q2
  • 2,372,777 records are known to have been breached in the confirmed attacks
  • Average ransom demand of $479,000
  • The most prolific ransomware strains with the highest number of claims against healthcare companies were INC (34), Qilin (25), SafePay (14), RansomHub (13), and Medusa (13)
  • INC and Qilin had the most confirmed attacks (10 each), followed by Medusa (7), RansomHub (6), and SafePay (4)

The research can be viewed at this link: https://www.comparitech.com/news/healthcare-ransomware-roundup-h1-2025/

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading