Desk live·
ForensicPost
Ransomware/Actors/File 25-0722

Interlock and Rhysida Worked Healthcare Without the Older Claimed Limits

Interlock, Rhysida and their peers worked healthcare through 2025 without the self-imposed limits older ransomware operations claimed to observe. The claimed limits were never enforceable anyway.

Constructed geometry · not a chart of case data
TargetHealthcare sector
ActorMultiple
S. Rosler11 min readConfidence: medium2 sources reviewed

Interlock held access to a dialysis provider for nineteen days, per 25-0412. Other operations worked hospitals, health systems and provider services through 2025 at the volumes this desk filed at 26-0426.

The Old Convention Was Always Marketing

Several established ransomware operations historically published rules claiming they would not target hospitals, and would supply free decryption if they hit one by accident.

That was never a constraint anyone could enforce. It was reputational positioning aimed at affiliates and at the law enforcement attention that healthcare attacks attract. Where it was observed at all, it was observed inconsistently.

The Affiliate Model Makes Stated Policy Meaningless

A ransomware-as-a-service operation does not choose its victims. Affiliates do, using access bought from brokers who sell whatever they have.

An operator publishing a healthcare exclusion is describing a preference it cannot implement, because the first time it knows the victim’s sector is frequently after encryption. This desk filed the affiliate dynamic at Qilin in 26-0705.

Why Healthcare Gets Hit Regardless Of Stated Ethics

The sector combines urgency that produces fast decisions, thin security capacity relative to data sensitivity, regulatory obligations that guarantee public disclosure, and the exact conditions this desk set out at 26-0330 for municipalities.

Graded medium: this is analysis across published incidents rather than a single sourced event, and stated group policies are self-reported claims we do not treat as evidence of behaviour.

How we reported this

This is an analysis file built on published incident reporting, listed below, read against files in this database. Group-published policies are actor claims and are labelled as such. Corrections: corrections@forensicpost.com.

Sources
  1. Ransomware in healthcare 2026: the attack timelineCybelAngel
  2. Hospitals under attack: ransomware in healthcare in 2025CyberGlobal
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary