Desk live·
ForensicPost
Ransomware/Healthcare/File 25-1211b

Medical Organisations Absorbed 22% of Disclosed Ransomware Attacks in 2025

Medical organisations accounted for a reported 22% of publicly disclosed ransomware attacks in 2025 — the highest concentration of any single sector globally.

Constructed geometry · not a chart of case data
TargetMedical organisations
ActorMultiple
S. Rosler12 min readConfidence: medium2 sources reviewed

Medical organisations accounted for approximately 22% of publicly disclosed ransomware attacks in 2025, described as the highest concentration of any single sector globally.

The Corpus Has An Explanation And Should Test It

This desk filed at 25-0630 that healthcare tops breach tables partly because it is the only sector legally compelled to count — a reporting artefact rather than a severity finding.

That argument does not transfer here, and the difference matters. This figure counts *publicly disclosed ransomware attacks*, largely derived from leak-site listings, not from the mandatory healthcare register. A leak site names whoever the attacker chose to name, regardless of sector reporting obligations.

So the visibility explanation is much weaker for this statistic than for the ones the corpus applied it to. Healthcare being 22% of leak-site listings is closer to a statement about targeting.

Which The Rest Of The Database Supports

The corpus recorded at 25-0722 that some groups decided hospitals were acceptable targets, and at 25-0715 that around one hospital in three reports care disruption from cyber incidents.

The mechanism is unpleasant and simple: a hospital cannot tolerate downtime, which raises the probability of payment, and the sector combines that pressure with the thin funding recorded at 26-0426 and the equipment constraints at 25-0729.

What Would Falsify It

If healthcare organisations are simply more numerous in the underlying victim population, or if the tracker over-samples US entities where healthcare disclosure is dense, the concentration would be partly artefactual after all.

This desk cannot rule that out — the denominator is not published, which is the objection at 25-1210b. Graded medium: the finding is more robust than most sector rankings in this corpus and is not established.

This is an analysis file

Built on published sector research, listed below. The underlying victim population and its geographic composition are not published. Corrections: corrections@forensicpost.com.

Sources
  1. Ransomware in healthcare: the attack timelineCybelAngel
  2. These are the biggest health data breaches in the first half of 2025Chief Healthcare Executive
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary