Ransomware Gangs Target EMEA Healthcare Supply Chain in Cyberattacks

www.news4hackers.com-ransomware-gangs-target-emea-healthcare-supply-chain-in-cyberattacks-ransomware-gangs-target-emea-healthcare-supply-chain-in-cyberattacks

A series of cyberattacks on healthcare entities across Europe, the Middle East, and Africa have revealed a shift in tactics by malicious groups focusing on interconnected systems rather than isolated facilities.

Research Findings

Research conducted by Flare analysts between 2024 and 2026 identified systematic exploitation of healthcare sector dependencies, including medical facilities, diagnostic centers, pharmaceutical networks, and software providers. The investigation highlighted that disruptions in these support systems can create cascading effects comparable to direct attacks on primary care institutions.

Threat Groups and Notable Breaches

The study cataloged 14 distinct threat groups engaging in healthcare-related operations, including Qilin, LockBit 3.0, RansomHub, DragonForce, Gunra, NightSpire, and 3AM. These actors targeted a broad spectrum of organizations, with some attacks directly impacting patient care while others served as precursors to more complex operations against critical infrastructure.

  • An American Hospital Dubai incident involving 40 terabytes of patient data and 450 million records
  • Spire Healthcare’s exposure of 1.8 terabytes of sensitive information
  • NRS Healthcare’s 578 gigabyte data leak
  • Genie Healthcare’s 110 gigabyte breach
  • Kazu, a smaller collective emerging in mid-2025, which expanded its focus from government entities to healthcare organizations in Latin America after initial attacks on Italian telemedicine platforms.

Financial Implications

Financial implications of these attacks have been substantial. In February 2024, the ALPHV/BlackCat group compromised Change Healthcare, a major US medical billing processor, stealing over six terabytes of health and financial data. The breach disrupted 40% of national medical claims processing, causing widespread delays in billing, prescriptions, and reimbursements. While the organization paid a $22 million ransom, total damages exceeded $2.87 billion when accounting for operational and reputational losses.

According to the Coalition for Health, Ethics Society, the European healthcare sector faced 289 cybersecurity incidents in 2024 alone, surpassing other critical infrastructure sectors.

Technical Vulnerabilities

Technical vulnerabilities exacerbate the crisis. Reports from the European Parliamentary Research Service and the Coalition for Health, Ethics Society indicate that many healthcare institutions rely on outdated technologies and fragmented IT systems, complicating security updates and incident response. These challenges are compounded by delayed regulatory compliance, staffing shortages, and the proliferation of connected medical devices.

Geopolitical Impact

Analysts note that operational disruption, rather than ransom payments, drives the majority of financial losses in European healthcare ransomware cases. The geopolitical dimension of these attacks has also grown, with researchers emphasizing their impact on national resilience and public health infrastructure.

Conclusion

Key findings from the study underscore the need for enhanced security measures across healthcare ecosystems, particularly for organizations serving as critical intermediaries in medical data and supply chains.



About Author

en_USEnglish