New research conducted by TrendAI shows that stolen healthcare and patient data is being sold and shared in an established ”underground” economy, where ransomware groups, access brokers and fraudsters collaborate to monetize patient information. Over a 12-month period, TrendAI analyzed 7,779 forum posts, 21,813 advertisements and 95 leaked ransomware pages linked to healthcare cybercrime.
The report shows that healthcare data remains particularly attractive to cybercriminals because the information is sensitive, long-lived and can be used for multiple types of fraud. Ransomware-related data sales accounted for 36.3 percent of marketplace activity, and the analysis also shows an increased focus on electronic health record system providers, where a single breach can impact hundreds of healthcare organizations.

– Healthcare data has evolved from stolen information like any other, to a long-term criminal asset, says Martin Fribrock, Country Manager Sweden, Finland and Baltics at TrendAI. And healthcare data is extra sensitive by nature, unlike, for example, a credit card or password, diagnoses, treatment history or biometric data cannot simply be blocked and replaced.

TrendAI warns that attacks on healthcare supply chains, such as healthcare software and medical platforms, are becoming an increasing risk factor and are enabling cybercriminals to scale attacks far beyond individual hospitals or clinics.
Read the report here.








