The healthcare sector is facing a sharp rise in ransomware attacks, hitting a four-year high in 2024, according to a Sophos report. Despite a global decline in ransomware, 67% of healthcare organizations were attacked in the past year, up from 60% in 2023. Recovery times have worsened, with only 22% of victims recovering in a week, down from 47% in 2023. Meanwhile, 37% took over a month to recover.
Ransom recovery costs surged to $2.57 million in 2024, and 57% of organizations paid more than what was demanded. The root causes include compromised credentials and exploited vulnerabilities, each responsible for 34% of attacks. Furthermore, cybercriminals have increasingly targeted backups, with 63% of organizations with compromised backups paying the ransom, compared to 27% for primary database attacks alone.
Insurance plays a major role in ransom payments, contributing to 77% of cases. The report advises healthcare organizations to adopt proactive, human-led threat detection to counter these evolving threats.