Healthcare organizations are having to pay millions to solve ransomware attacks

Ransomware attack on a computer
(Image credit: Kaspersky)

Healthcare organizations continue to be attractive targets for ransomware criminals, and these attacks are not only becoming more frequent, but also more expensive, with the average costing $2.57 million to recover from - a rise from $2.2 million the previous year, new research has claimed.

A report from Sophos found over two-thirds (67%) said they had been victims of a ransomware attack in 2024, up from 60% in 2023.

The complexity and sophistication of attacks is growing too, as 80% of organizations took over a week to recover, considerably more than the 46% reported in 2022.

Vulnerable targets

The healthcare industry has long been a lucrative target for cybercriminals, since organizations tend to hold highly sensitive information and need constant access to ensure patient safety.

Attackers primarily used exploited vulnerabilities and compromised credentials to gain access to the organizations, accounting for 34% of instances each. Criminals didn’t just go after the data, in 95% of attacks, hackers also went after organizations' backup. Understandably so, since a compromised backup means the ransom is twice as likely to be paid.

“Unfortunately, cybercriminals have learned that few healthcare organizations are prepared to respond to these attacks, demonstrated by increasingly longer recovery times.” said Chief Technical Officer at Sophos, John Shier.

“These attacks can have immense ripple effects, as we’ve seen this year with major ransomware attacks impacting the healthcare industry and impacting patient care”

Without huge cybersecurity budgets and often with outdated IT systems, healthcare institutions are exposed. Research suggested as much as 50% of IT systems would fall under the ‘legacy’ category, leaving them open to vulnerabilities.

With cybercriminals becoming more successful and more destructive, Shier calls for a more proactive, ‘human-led’ approach to threat detection, calling for continuous monitoring to stay ahead of cybercriminals.

More from TechRadar Pro

Ellen Jennings-Trace
Staff Writer

Ellen has been writing for almost four years, with a focus on post-COVID policy whilst studying for BA Politics and International Relations at the University of Cardiff, followed by an MA in Political Communication. Before joining TechRadar Pro as a Junior Writer, she worked for Future Publishing’s MVC content team, working with merchants and retailers to upload content.

Read more
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
More reports claim 2024 was the worst year for ransomware attacks yet
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
healthcare
US government wants to toughen up cybersecurity rules for healthcare organizations
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Less than half of ransomware incidents end in payment - but you should still be on your guard
Flags of Iran, China, Russia and North Korea on a wall. China North Korea Iran Russia alliance
Cybercrime is helping fund rogue nations across the world - and it's only going to get worse, Google warns
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
UK private health services firm told to pay up $2m for ransomware hit
Latest in Pro
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
A fresh Samsung Galaxy S25 Edge leak hints at a 2K display and a titanium frame