Health-ISAC Finds Ransomware & Third-Party Breaches Dominate 2025 Threats

The healthcare sector is facing an intensifying cybersecurity crisis as ransomware attacks and third-party breaches emerge as the most significant threats to hospital systems, according to the “2025 Health Sector Cyber Threat Landscape” report by Health-ISAC.
The findings reveal the increasing sophistication of cybercriminal operations and the growing role of nation-state actors in targeting healthcare institutions. “The nature of cyber threats has shifted. Attackers are not just locking systems—they’re targeting the most vulnerable points in the healthcare ecosystem,” the report said.
Ransomware remains the top concern for health systems in 2025, with Health-ISAC tracking 458 ransomware incidents in the past year. The report identifies the most active ransomware groups, including LockBit 3.0, which was responsible for 52 attacks on healthcare organizations. The INC Ransomware and RansomHub collectively accounted for dozens of breaches.
Read the full article in HealthSystemCIO.org. Click Here
- Related Resources & News
- New Cybersecurity Policies Could Protect Patient Health Data
- CyberWire Podcast: PHP flaw sparks global attack wave
- Health-ISAC Hacking Healthcare 3-14-2025
- HSCC Aiming to Identify Healthcare Workflow Chokepoints
- New Healthcare Security Benchmark Highlights Key Investment Priorities and Risks
- Are Efforts to Help Secure Rural Hospitals Doing Any Good?
- CISA cuts $10 million annually from ISAC funding for states amid wider cyber cuts
- 2024 Health-ISAC Discussion Based Exercise Series After-Action Report
- Cobalt Strike takedown effort cuts cracked versions by 80%
- Denise Anderson recognized on Cyber25 Women of Impact list