The most active groups against US healthcare providers in 2025 were reported as Qilin, INC Ransom, Akira, RansomHub and Interlock.
None Of Them Is A Healthcare Specialist
Qilin was the most prolific operation overall at 25-1108, dominated telecom at 25-1109, and claimed a Japanese brewer at 25-1101. Akira was linked to the Marquis compromise at 25-0814. RansomHub absorbed LockBit’s vacated share at 25-0402. Interlock appears at DaVita in 25-0412 and in the healthcare actor file at 25-0722.
The corpus argued at 25-1109 that sector concentration is probably an affiliate artefact — the largest platforms receive whatever access affiliates bring, so they dominate every sector rather than specialising in any.
This list supports that. Five names, five sectors, one explanation.
Which Complicates The Targeting Finding
At 25-1211b this desk argued that healthcare’s 22% share of disclosed attacks is closer to a targeting statement than a visibility artefact, and cited the payment-pressure mechanism at 25-0722.
If the same five generalist platforms lead in healthcare, telecom and manufacturing, the concentration may be a property of the affiliate market rather than a deliberate sector choice — access flows to the biggest platforms, and healthcare produces a lot of accessible targets.
Both readings are live and the corpus cannot resolve them. Recording that is more useful than choosing.
And Naming Groups Is Decreasingly Informative
The corpus filed at 25-1226 that 2025 produced 124 active groups including 73 new entrants, and at 25-1004 that the top ten’s share of leak-site postings fell from 71% to 56% across three quarters.
A list of five names describes the head of a distribution with a very long tail. The defensive implication at 25-1004 stands: controls should be organised around technique rather than actor.
Built on published sector research, listed below, read against the actor files in this database. Corrections: corrections@forensicpost.com.
- Ransomware in healthcare: the attack timelineCybelAngel
- Record number of ransomware victims and groups in 2025Infosecurity Magazine