Cybercrime DB

Critical Infrastructure Ransomware Attacks and Response

Attackers target hospitals and utilities where downtime costs lives and backups get destroyed.

Editor at Large · · 10 min read
Cover illustration for “Critical Infrastructure Ransomware Attacks and Response”
ransomware groups and operators · August 19, 2026 · 10 min read · 2,338 words

Ransomware operators love critical infrastructure for one reason: the math works in their favor. KELA logged 2,332 ransomware incidents against critical infrastructure in the first nine months of 2025, half of all global ransomware activity, up 34% year over year. Three things line up for attackers here. Hospitals and utilities can't tolerate downtime the way a retailer can, the equipment running these places is old and hard to patch, and oversight is split across a dozen agencies with a dozen different rulebooks, so nobody's fully in charge.

The US carries roughly 1,000 of those incidents (about 21% of the global total), with Canada, Germany, the UK, and Italy filling out the rest of the top five. Criminals are good at spreadsheets, and they've clearly run the numbers on what happens when critical systems go dark. A locked hospital means patients don't get treated, and a locked water utility means a town doesn't get clean water. Insurance covers a lot, but it doesn't cover a dialysis patient who missed her appointment because the scheduling system got encrypted. Operators pay ransoms because waiting for a "technically possible" recovery has a human cost nobody's willing to eat. Attackers know this, and it's the whole business model.

Which sectors are being hit hardest and what the targeting pattern reveals

Diagram: Where Ransomware Hits Critical Infrastructure Hardest. Visualizes: Show the three most-targeted critical infrastructure sectors ranked by a key severity metric, using concrete figures from KELA and IBM 2025 data.

KELA's 2025 data shows manufacturing incidents jumped from 520 to 838 year over year, a 61% increase, the steepest growth curve of any sector. The reason isn't mysterious: a shutdown at one plant ripples immediately beyond it. Jaguar Land Rover and Bridgestone both found this out when production halts spread into their supply chains within hours. The real cost is every downstream partner suddenly unable to get parts, dwarfing the ransom demand itself.

Healthcare stays the most expensive sector to breach, full stop. IBM's Cost of a Data Breach Report 2025 put the average healthcare breach at $7.42 million, the highest of any industry for fourteen years running. The FBI confirmed 238 ransomware events against US healthcare providers in 2024. This makes it a target painted in bright red on every attacker's map.

Energy and utilities carry a different flavor of the same problem. Sophos found 67% of organizations in the sector got hit in 2024. Here's the number that should stop you mid-sip of coffee: 98% of those attacked said adversaries specifically went after their backups, deliberately, nearly every single time. A company with no backups has exactly one option left, and that's the option the attacker is banking on.

The three sectors share a root cause. Attackers go where downtime hurts most and where the technology is a patchwork of new IT bolted onto decades-old operational hardware that nobody can patch overnight. So how are they actually walking through the door?

How ransomware groups actually get in: the common initial access methods

The big three ransomware-as-a-service crews in 2025, Akira, Qilin, and Lynx, don't need anything fancy. Steal credentials, exploit a known vulnerability, kill the security software, delete the backups, encrypt the files. Rinse, repeat, next victim.

Change Healthcare is the case everyone cites, and it's a rough one to sit with. Attackers got in through a Citrix portal around February 12, 2024, using compromised credentials, with no multi-factor authentication on that portal, a control that's basically a seatbelt at this point. It was missing entirely on a system that ended up disrupting claims processing for roughly half of all US medical claims. One missing checkbox, catastrophic result.

Exploiting known vulnerabilities has grown right alongside credential theft through 2025 as a dominant entry method. Attackers walk through doors that have been unlocked for months, sometimes years, because someone deprioritized a patch cycle or never got around to rotating a password. Zero-days are surplus to requirements.

CodeRED/OnSolve, hit in November 2025, shows a variation on the theme. Attackers compromised an emergency alert platform, the kind that texts you when a tornado's coming, and held resident contact data for ransom. They targeted the third-party vendor those governments relied on, the same structural weak point that sank Change Healthcare, a claims processor sitting in the middle of the pipeline. That breach still touched 900,000 physicians, 33,000 pharmacies, 5,500 hospitals, and 600 laboratories. Compromise the plumbing, and everyone downstream gets wet.

What happens between initial access and operational disruption: the escalation window

Getting in the door is step one. The real damage gets built quietly after that, over days or sometimes weeks, while attackers move sideways through the network, hunt for backup infrastructure, and siphon data out the back door before ever pulling the trigger on encryption.

That backup-hunting is methodical, and it's the same 98% figure from Sophos showing up again: energy and utilities victims whose backups got specifically targeted. Backups are the escape hatch, and attackers want to weld it shut before the victim even knows there's a fire.

Critical infrastructure carries a particular vulnerability here: IT and operational technology are often connected in ways nobody fully mapped. Steal a login for the billing system, and you might find a path straight into the machinery controlling physical processes, valves, pumps, turbines, whatever keeps the lights on. Defenders frequently don't know that pathway exists until someone's already walked it.

Change Healthcare's timeline captures the gap well. The Citrix breach happened around February 12; the public didn't see the fallout for days, and by then the data was already gone. Double extortion enters here too, standard practice now for Akira, Qilin, and Lynx alike. Pay to get your files back, then pay again so they don't publish what they stole. Restoring from a clean backup, assuming one still exists, leaves that second half of the threat fully intact. The window is finite, sure, but by the time anyone notices they're inside it, most of the decisions that mattered got made years earlier, back when somebody decided whether or not to segment the network.

The operational disruption ransomware causes in critical infrastructure settings

Change Healthcare remains the go-to case study, and for good reason. One third-party system going dark disrupted claims processing for 900,000 physicians, 33,000 pharmacies, 5,500 hospitals, and 600 laboratories. A March 2024 survey of nearly 1,000 hospitals by the American Hospital Association found 74% reported direct impact on patient care, including delays in authorizations for medically necessary treatment. Patients waited longer for the actual care they needed.

The financial side is its own kind of staggering. Kodiak Solutions estimated the attack caused a $6.3 billion drop in submitted claims across its 1,850 hospital and 250,000 physician clients in just the first three weeks. That's one slice of everyone affected, not the whole pie.

CodeRED shows a different flavor of disruption. Knocking out emergency alert infrastructure across multiple states is a public safety problem first and a cybersecurity problem second; no ransom negotiation brings the system back online while it's still down. Manufacturing tells a related story, with Jaguar Land Rover and Bridgestone both watching ransomware jump from IT systems into the physical production line, halting output and rattling supply chains well beyond their own walls. The common thread across all three: the worst disruptions happen where digital systems and physical operations are wired tightly together, with no manual fallback when the computers stop working.

What response looks like in the first hours and why those decisions compound

Diagram: Paying the Ransom Is a Coin Flip. Visualizes: Visualise the branching outcome of a ransom payment decision using the verified 2025 figures.

The first few hours of a critical infrastructure ransomware incident force four decisions at once: isolate systems or keep running, call law enforcement, check whether backups are intact, figure out if operational technology got touched. They collide, usually while someone's phone is ringing off the hook.

Isolation is the knottiest of the four. Cutting a network segment to stop the spread might cause the exact disruption the attacker was hoping for. A hospital can't power down its clinical systems on a whim, and a water utility can't yank its SCADA system offline without a manual process ready to take over, which most utilities don't have sitting on a shelf somewhere.

Change Healthcare shows what delay costs in real numbers. UnitedHealth Group reported $1.521 billion in direct breach response costs and $2.457 billion in total cyberattack impacts for the nine months ending September 2024. Numbers that size come from a slow, tangled response.

Checking backup integrity has to happen immediately, but given that Sophos found attackers targeted backups in 98% of energy sector cases, there's a decent chance the backups are already compromised by the time anyone gets around to checking. That discovery, mid-incident, changes the entire recovery math. UnitedHealth paid roughly $22 million to ALPHV/BlackCat, and then a second group, RansomHub, showed up claiming they had the same data and wanted their own payday. Once the data is out the door, extortion continues beyond the first payment.

In 2025, 41% of organisations paid a ransom. Of those, only 67% got their data back in full. That means roughly one in three payments produced no full recovery. Paying is a coin flip dressed up as a solution. The alternative, restoring from clean backups, only works if those backups exist, are actually clean, and have been tested ahead of time, which loops back to decisions made long before anyone knew an attack was coming. Law enforcement matters here too: the FBI's IC3 received more than 2,100 critical infrastructure ransomware reports in 2025, and early notification can unlock threat intelligence or decryption tools recovered from prior takedowns. Too many organizations still wait too long to pick up that phone.

What CIRCIA changes about the reporting obligation and why it reshapes incident response planning

The Cyber Incident Reporting for Critical Infrastructure Act adds a legal clock to all of this. Covered entities now have to report a covered cyber incident within 72 hours, and any ransomware payment within 24 hours of making it. That's a deadline ticking while the fire's still burning.

CISA wants a better national picture of the threat, and pulling this data into one place is a reasonable way to get it. Fair enough. But for the organization in the middle of the incident, the immediate effect is a compliance deadline stacked directly on top of an unresolved crisis. Two workstreams, both demanding attention simultaneously.

That 24-hour window for reporting a ransom payment is shorter than most companies' internal approval chain for spending money on anything, let alone a multimillion-dollar payment to criminals. Skip the pre-authorization on who makes that call and how fast, and you'll miss the deadline even when paying was the correct decision.

Any incident response plan drafted before CIRCIA's rules were finalized needs a rewrite. The regulatory piece is baked into the incident from minute one now. Guidance from PwC and IAPP both land on the same point: get ready before the incident hits, run tabletop exercises, name your reporting contact ahead of time, and brief legal counsel on the clock before it starts ticking.

How law enforcement disruptions affect the threat landscape without resolving it

Operation Cronos, led jointly by UK and US authorities across ten countries, seized LockBit's infrastructure and froze more than 200 cryptocurrency accounts, the most coordinated ransomware takedown on record. The criminal ecosystem absorbed the blow and kept moving.

RansomHub filled the gap LockBit left, then shut itself down in April 2025. Many of its affiliates simply moved to Qilin, whose monthly victim count nearly doubled in the second quarter of 2025, according to Check Point. The affiliate model means the people doing the actual hacking simply log into a different platform when one brand goes dark, same skills, new logo.

LockBit itself came back in September 2025 as LockBit 5.0, complete with dedicated payloads for Windows, Linux, and VMware ESXi. Even the most successful takedown in ransomware history proved temporary.

Here's the part worth sitting with: among 103 active ransomware groups in 2025, just five, Qilin, Clop, Akira, Play, and SafePay, accounted for nearly a quarter of all incidents. The underground is consolidating and professionalizing rather than scattering into chaos. Law enforcement did slow the growth rate, from 77% year-over-year in 2023 down to 15% in 2024, a real win worth counting. Slower growth is still growth, though, and every organization carries real risk regardless of which groups get raided. Resilience has to hold regardless of which criminal brand happens to be in fashion this quarter.

What structural resilience looks like for critical infrastructure operators

Change Healthcare's breach traces back to a single Citrix portal missing multi-factor authentication, a control gap that eventually touched 100 million Americans and cost UnitedHealth Group $2.457 billion in total impacts. Start with MFA. That's the cheapest lesson in this whole piece, and also the most expensive one to ignore.

Backups need to be a pre-incident discipline, established well before the ransom note shows up. With 98% of energy and utilities victims reporting their backups were targeted, an offline or immutable copy the production network literally cannot reach is the floor you build everything else on.

IT and OT segmentation decides whether a stolen credential turns into a plant shutdown or stays boxed in where it can't do much harm. Manual fallback procedures for operational systems are what turn isolation into a workable choice. Third-party risk deserves the same seriousness. Change Healthcare and OnSolve/CodeRED both prove that one vendor's bad day can become hundreds of organizations' bad month, so mapping who you depend on, and how secure they actually are, is risk management.

Response plans need CIRCIA's clock built in from the start, 72 hours for incident reporting, 24 hours for ransom payment reporting, with contacts and legal counsel briefed well before anything happens. Tabletop exercises that simulate the worst version of the isolation decision, including a scenario where the backups turn out to already be compromised, are the only real way to find out if the first-hour plan survives contact with reality. Sophos put the mean recovery cost in energy and utilities at $3.12 million, excluding any ransom paid. Against a number like that, the case for building resilience ahead of time is straightforward. It just has to be made before the attack, because nobody wants to hear it during one.

Sources

  1. industrialcyber.co

More in ransomware groups and operators