Healthcare Ransomware Attacks Increased in Q1, 2025

Several reports published this month on the current state of ransomware indicate Q1, 2025 has been a record-breaking quarter for attacks. The rise in attacks appears to be in response to the increasing reluctance of victims to pay the ransom demand, with ransomware groups responding by increasing the volume of attacks.

The increased reluctance to pay a ransom stands to reason, as the attack on Change Healthcare last year clearly demonstrated that ransomware groups cannot be trusted. A ransom demand was issued by the BlackCat group, payment of which was required to prevent the publication of the stolen data. A $22 million ransom was paid only for the group to perform an exit scam, pocketing the funds and shutting down the operation. The affiliate behind the attack still had a copy of the data and partnered with the RansomHub group, which attempted another extortion attempt.

GuidePoint Security’s Research and Intelligence Team (GRIT) identified 2,063 victims of ransomware attacks in Q1, 2025, a historic high. Not only have attacks increased, but so too has the number of active ransomware groups, with at least 70 known groups conducting attacks, an increase of 55.5% from the same time last year. The increase in active groups has been linked to the shutdown of a major player in the ransomware ecosystem – ALPHV/BlackCat – and law enforcement actions against another prolific ransomware group – LockBit. As a result, experienced affiliates are thought to have formed their own groups. It is, of course, too early to tell whether the increase in attacks represents a short-term spike or if 2025 will turn out to be a particularly bad year for ransomware attacks.

While healthcare remains a key target for ransomware groups, the manufacturing, retail/wholesale, and technology industries were the most attacked industries, with healthcare in the fourth spot. GRIT also reports a notable increase in attacks on the non-profit sector, which doubled from the previous quarter.

ReliaQuest also published a report with similar findings, with its data showing a 23% jump in ransomware attacks from Q4, 2024, and a 30% spike in attacks on targets in the United States. The firm notes that a new record was set in December 2024 for additions to data leak sites, with that record smashed in February 2024, largely due to a campaign conducted by the Clop group involving the mass exploitation of a vulnerability in the Cleo Managed File Transfer (MFT) solution, with almost 400 companies attacked. RansomHub was the second most active group, followed by Akira, Qilin, Lynx, and Play. While only the 10th most active group, Medusa has been conducting attacks in increasing volume, especially on critical infrastructure such as healthcare.

BlackFog similarly reports a record-breaking quarter for ransomware attacks, with 2,124 undisclosed attacks – a 113% increase from the same period last year – and 278 disclosed attacks, which were up 45% compared to Q1, 2024. BlackFog puts March down as the most active month in the quarter with 107 disclosed attacks, up 81% from March 2024. Healthcare accounted for the highest number of disclosed attacks in Q1, 2025, with 57 of the 278, although entities in the sector are more likely to disclose attacks as it is a requirement of HIPAA.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

Comparitech released its report for Q1, 2025, having tracked 2,190 attacks in total over the quarter, with 197 of those confirmed by victims.  Comparitech reports a 32% increase in attacks on the healthcare sector compared to Q1, 2024, with 123 attacks in total and 93 of those confirmed by victims.  Across those attacks (where the ransom payment is known), healthcare organizations paid an average of $860,000, with the largest ransom of $2 million paid to the Medusa group by HCRG Care Group in the United Kingdom.

Most recently, the law firm BakerHostetler published a report based on an analysis of the 1,250+ incidents the firm assisted with last year and suggests that ransomware may be in decline. The firm was involved in fewer attacks and reports of falling ransom payments. The firm suggests that in response, threat actors have been increasingly engaging in fraudulent wire transfers rather than ransomware deployment, with fraudulent transfers increasing by 302% year over year. The average wire transfer was $1,256,797, and the median was $130,000. The average ransom payment was $916,203, or $501,338 if the largest payment is not included in the figures, which shows fraudulent wire transfers can be just as profitable, if not more, than ransomware deployment. The figures for healthcare show an average payment of $847,875 and a median payment of $375,000.

BakerHostetler suggests that after some chaotic years, “ransomware is settling into the category of risk that still exists but for which there are known measures that should make an impactful attack less likely.” The firm may have a different opinion by the time next year’s report is published, given the increase in attacks in Q1, 2025. BakerHostetler’s data does show that healthcare remains the biggest target for ransomware groups, accounting for 36% of the ransomware attacks that the firm was involved with. These attacks often cause major disruption to patient care and cause significant loss of revenue.

The firm does have some good news, and that is falling breach costs, with one of the main direct costs – forensic analysis – falling for the third straight year, from $50,125 in 2023 to $41,145 in 2024. The firm reports decreased use of malware by threat actors due to increased use of compromised credentials and living-off-the-land techniques, with the lack of malware leading to faster containment and investigations, which helps to bring costs down. The average time of containment was down from 33 days in 2023 to 26 days in 2024, although the time from the attack to notification increased from 60 days to 63 days.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/