Healthcare ransomware attacks rose about 14% in the first half of 2026. Underneath that figure the distribution shifted: attacks on hospitals held roughly flat, while attacks on the businesses around providers — billing firms, manufacturers, drug wholesalers — rose close to 35%. Manufacturers specifically rose around 36%.
Hospitals Got Harder; The Sector Did Not
Flat hospital numbers are a plausible sign that years of investment and regulatory attention have raised the cost of attacking providers directly. That is a genuine result.
It has not reduced harm, because the operators have not left the sector. They have moved one step upstream to organisations with the same downstream reach and less scrutiny — the pattern this desk filed in 26-0731, 26-0716 and 26-0214.
Displacement Is The Expected Outcome
Where an adversary is motivated by revenue rather than by a specific target, hardening one class of victim redistributes attacks rather than preventing them. The operators are indifferent to which organisation pays.
That has an uncomfortable implication for how success is measured. A programme that reduces incidents at the organisations it covers, while incidents rise at their suppliers, can report improvement on every metric it owns.
The number worth tracking is not provider incidents. It is patients affected by any incident anywhere in the chain — and almost nobody publishes that.
This is an analysis file built on published sector research, listed below. Percentages are as reported by the analysts; counting rules vary between studies. Corrections: corrections@forensicpost.com.
- Healthcare ransomware attacks shift: businesses up 35% while hospitals hold flatCybersecurity Insiders
- Healthcare ransomware roundup: H1 2026 stats on attacks, ransoms, and data breachesComparitech
- Healthcare ransomware attacks up 14%: 5 things to knowBecker’s Hospital Review