INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Medical institution suffers 9 out of 10 ransomware attacks
| 2026-10-09 12:00 CRITICAL LOW RANSOMWARE & EXTORTION CYBERATTACK (GENERAL)
Executive Summary
AI-generated
In the third quarter of 2026, ransomware attacks reached their highest ever quarterly volume, with a total of 2627 claimed attacks reported by Comparitech. This represents a 27% increase on the previous quarter and a 61% rise compared to Q3 2025. The finance and technology sectors experienced significant growth in ransomware incidents, up by 72% and 70%, respectively. Other critical sectors such as education (up 50%), healthcare (39%), government (36%) and utilities (32%) also saw a notable increase in attacks. Attackers are increasingly using triple extortion tactics, targeting individuals impacted in the attack, with examples including The Gentlemen's recent attack on MIP Holdings.
Technical Mitigations AI-generated
• Use of IP spoofing techniques to mask the origin of attacks, making it difficult for investigators to identify the attackers.
• Triple extortion tactics employed by ransomware groups, such as targeting individuals impacted in the attack and publishing stolen data online.
• AI-powered ransomware campaigns, like JadePuffer, which enable attackers to increase the scale and speed of their operations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
INC RansomINC RansomShinyHuntersShinyHunters
QilinQilin
Target & Sectors
EUROPE
EUROPE
DACH
DACH
LATAM
LATAM
AFRICA
AFRICA
NORTH_AMERICA
NORTH_AMERICA
technologytechnology
energyenergy
financefinance
manufacturingmanufacturing
healthhealth
Incident Timeline
Q3 2025
The medical institution experienced a 61% rise in cyberattacks compared to Q3 2025, with the current quarter seeing a 27% increase on that figure.
Click on any entity below to view its context and source!
general_metric
27 %
This is a 27% increase on the previous quarter, Q2 2026, and a 61% rise compared to Q3 2025.
general_metric
61 %
This is a 27% increase on the previous quarter, Q2 2026, and a 61% rise compared to Q3 2025.
2025/10/08
Threat actors used ransomware to target a medical institution, resulting in 16 reported incidents nationwide as of August this year.
Click on any entity below to view its context and source!
general_metric
16 incidents
As of August this year, 16 incidents have been reported, exceeding the number of incidents reported last year.
2025/10/09
Threat actors suspected to be from China leaked the personal data of approximately 2,970,000 customers from Lotte Card and SC First Bank in October 2025.
Click on any entity below to view its context and source!
organisation
Lotte Card
Last year, approximately 2,970,000 customers' information was leaked from Lotte Card and SC First Bank, which was suspected to be a Chinese attack.
organisation
SC First Bank
Last year, approximately 2,970,000 customers' information was leaked from Lotte Card and SC First Bank, which was suspected to be a Chinese attack.
source_region
China
Last year, approximately 2,970,000 customers' information was leaked from Lotte Card and SC First Bank, which was suspected to be a Chinese attack.
victims
2,970,000 customers
Last year, approximately 2,970,000 customers' information was leaked from Lotte Card and SC First Bank, which was suspected to be a Chinese attack.
Q2 2026
The finance and technology sectors saw a 72% increase in ransomware incidents compared to Q2 2026.
Click on any entity below to view its context and source!
tactic
Ransomware
The finance and technology sectors experienced the biggest growth in ransomware incidents in Q3 compared to Q2 2026, up by 72% and 70%, respectively.
organisation
Q3
The finance and technology sectors experienced the biggest growth in ransomware incidents in Q3 compared to Q2 2026, up by 72% and 70%, respectively.
general_metric
72 %
The finance and technology sectors experienced the biggest growth in ransomware incidents in Q3 compared to Q2 2026, up by 72% and 70%, respectively.
general_metric
70 %
The finance and technology sectors experienced the biggest growth in ransomware incidents in Q3 compared to Q2 2026, up by 72% and 70%, respectively.
general_metric
27 %
This is a 27% increase on the previous quarter, Q2 2026, and a 61% rise compared to Q3 2025.
general_metric
61 %
This is a 27% increase on the previous quarter, Q2 2026, and a 61% rise compared to Q3 2025.
Q3 2026
Ransomware exploited a vulnerability in medical institution systems, targeting nationwide patient safety.
Click on any entity below to view its context and source!
tactic
Ransomware
Q3 2026 Sets New Record for Ransomware Attacks.
June 2026
MIP paid a ransom to have stolen data deleted after being targeted by the group in June 2026.
Click on any entity below to view its context and source!
organisation
MIP
After being targeted by the group in June 2026, MIP paid a ransom to have stolen data deleted.
July 2026
Threat actors Everest issued a ransom demand of $12.3m against Stadler Rail, a Swiss-based railway manufacturing firm, in July 2026.
Click on any entity below to view its context and source!
target_region
Switzerland
The most hefty demand known to be issued in the period was $12.3m, against Swiss-based railway manufacturing firm Stadler Rail by Everest in July 2026.
August 2026
Ransomware attacks affected 1073 companies in August 2026, according to NCC Group's Cyber Threat Intelligence Report.
Click on any entity below to view its context and source!
tactic
Ransomware
According to NCC Group’s
Cyber Threat Intelligence Report for August 2026
,
published on September 23
, 1073 companies fell victim to ransomware attacks during the month.
attribution
NCC Group’s
According to NCC Group’s
Cyber Threat Intelligence Report for August 2026
,
published on September 23
, 1073 companies fell victim to ransomware attacks during the month.
2026/09/23
Ransomware operators claimed 179 victims across over 50 countries and islands between September 21st and September 27th, 2026.
Click on any entity below to view its context and source!
tactic
Ransomware
Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 21st September and 27th September 2026, kindly assisted by our partners.
DBD discovered and researched
179 Ransomware Victims
over
50 Countries and Islands
claimed by
47 Data-Leaking Ransomware Operators
, including
3 Newly Discovered Ransomware Operators
last week.
organisation
ROC Report
Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 21st September and 27th September 2026, kindly assisted by our partners.
general_metric
50 %
DBD discovered and researched
179 Ransomware Victims
over
50 Countries and Islands
claimed by
47 Data-Leaking Ransomware Operators
, including
3 Newly Discovered Ransomware Operators
last week.
organisation
Data-Leaking Ransomware Operators
DBD discovered and researched
179 Ransomware Victims
over
50 Countries and Islands
claimed by
47 Data-Leaking Ransomware Operators
, including
3 Newly Discovered Ransomware Operators
last week.
financial
179 Ransomware Victims
DBD discovered and researched
179 Ransomware Victims
over
50 Countries and Islands
claimed by
47 Data-Leaking Ransomware Operators
, including
3 Newly Discovered Ransomware Operators
last week.
financial
47 Leaking Ransomware Operators
DBD discovered and researched
179 Ransomware Victims
over
50 Countries and Islands
claimed by
47 Data-Leaking Ransomware Operators
, including
3 Newly Discovered Ransomware Operators
last week.
financial
3 Discovered Ransomware Operators
DBD discovered and researched
179 Ransomware Victims
over
50 Countries and Islands
claimed by
47 Data-Leaking Ransomware Operators
, including
3 Newly Discovered Ransomware Operators
last week.
September 23
Ransomware attacks affected 1073 companies in August 2026, according to NCC Group's Cyber Threat Intelligence Report published on September 23.
Click on any entity below to view its context and source!
tactic
Ransomware
According to NCC Group’s
Cyber Threat Intelligence Report for August 2026
,
published on September 23
, 1073 companies fell victim to ransomware attacks during the month.
attribution
NCC Group’s
According to NCC Group’s
Cyber Threat Intelligence Report for August 2026
,
published on September 23
, 1073 companies fell victim to ransomware attacks during the month.
October 7
Ransomware demands averaged $602,400 in the third quarter of 2023.
Click on any entity below to view its context and source!
tactic
Ransomware
The Comparitech report,
published
on October 7, found that the average ransomware demand in Q3 was $602,400.
financial
$602,400 Q3
The Comparitech report,
published
on October 7, found that the average ransomware demand in Q3 was $602,400.
July to September 2026
Threat actors launched a ransomware attack on the medical institution, resulting in 2627 claimed attacks nationwide from July to September 2026.
2021 to 2026
Threat actors used ransomware to target hospitals in Korea, resulting in 109 reported cyber attacks between 2021 and 2026.
Click on any entity below to view its context and source!
attribution
the Health and Welfare Committee
According to the Health and Welfare Committee of the National Assembly, data submitted by the Ministry of Health and Welfare shows that there were 109 reported cyber attacks on hospitals in Korea from 2021 to 2026.
organisation
the National Assembly
According to the Health and Welfare Committee of the National Assembly, data submitted by the Ministry of Health and Welfare shows that there were 109 reported cyber attacks on hospitals in Korea from 2021 to 2026.
organisation
the Ministry of Health and Welfare
According to the Health and Welfare Committee of the National Assembly, data submitted by the Ministry of Health and Welfare shows that there were 109 reported cyber attacks on hospitals in Korea from 2021 to 2026.
general_metric
109 reported cyber attacks
According to the Health and Welfare Committee of the National Assembly, data submitted by the Ministry of Health and Welfare shows that there were 109 reported cyber attacks on hospitals in Korea from 2021 to 2026.
39 2026
Threat actors using ransomware launched a nationwide cyberattack on medical institutions in Week 39 of 2026.
Click on any entity below to view its context and source!
organisation
Ransomware
Ransomware Operator Claims - Week 39 2026.
2026/10/09
The Gentlemen and Qilin dominated ransomware activity in Q3, claiming 342 and 357 attacks respectively.
Click on any entity below to view its context and source!
organisation
CrowdStrike
The US security company CrowdStrike suggested that the attacker's background was likely a 26-year-old person living in Guangdong Province, China.
organisation
The US Food and Drug Administration
The US Food and Drug Administration (FDA) has also reported on the cybersecurity of medical devices as a matter of patient safety.
organisation
FDA
The US Food and Drug Administration (FDA) has also reported on the cybersecurity of medical devices as a matter of patient safety.
organisation
NCC
Other sectors which faced high levels of disruption from ransomware attacks included consumer goods and service (18%),
healthcare
(12%), information technology (11%) and financial services (6%).
Notable incidents during August, as referenced in the NCC report, included a cyber-attack which targeted Boston Dynamics and a data breach by hackers which affected
Manchester Airport Group
.
organisation
Boston Dynamics
Other sectors which faced high levels of disruption from ransomware attacks included consumer goods and service (18%),
healthcare
(12%), information technology (11%) and financial services (6%).
Notable incidents during August, as referenced in the NCC report, included a cyber-attack which targeted Boston Dynamics and a data breach by hackers which affected
Manchester Airport Group
.
organisation
Manchester Airport Group
Other sectors which faced high levels of disruption from ransomware attacks included consumer goods and service (18%),
healthcare
(12%), information technology (11%) and financial services (6%).
Notable incidents during August, as referenced in the NCC report, included a cyber-attack which targeted Boston Dynamics and a data breach by hackers which affected
Manchester Airport Group
.
organisation
The Gentlemen Dominate Ransomware
Qilin and The Gentlemen Dominate Ransomware Activity
Qilin
and
The Gentlemen
were the most prolific ransomware groups in Q3, claiming 357 and 342 attacks, respectively.
threat_actor
ShinyHunters
Read now: ShinyHunters Claim Hack of Rival Ransomware Gang Clop
There was also a big rise in claimed attacks by Direwolf during the same period, up by 1450%.
organisation
Direwolf
Read now: ShinyHunters Claim Hack of Rival Ransomware Gang Clop
There was also a big rise in claimed attacks by Direwolf during the same period, up by 1450%.
organisation
Gunra
Last July, the international ransomware organization 'Gunra' attacked Seoul Fire Insurance, disrupting its computer services for approximately 64 hours.
organisation
Seoul Fire Insurance
Last July, the international ransomware organization 'Gunra' attacked Seoul Fire Insurance, disrupting its computer services for approximately 64 hours.
organisation
Ransomware
Ransomware accounted for 98 incidents, or 89.9% of the total, while the remaining 11 incidents were categorized as information exposure, account takeover, malicious code infection, file deletion, cryptocurrency mining, and others.
organisation
Gangwon National Hospital
Cyberattack on medical institutions' ransomware attack revealed the risks this year, specifically in the accidents at Gangwon National Hospital and Jeonnam National Hospital.
organisation
Jeonnam National Hospital
Cyberattack on medical institutions' ransomware attack revealed the risks this year, specifically in the accidents at Gangwon National Hospital and Jeonnam National Hospital.
organisation
CT
The two hospitals experienced a ransomware attack that disrupted their medical image storage and transmission system (PACS), making it difficult for medical staff to verify MRI and CT scan results in the operating room.
organisation
the Victim Names and Industry Sectors
For further analysis on these (and any historic) Ransomware Operator Claims, including the Victim Names and Industry Sectors attacked, please use our
PRiSM
application.
victims
1000 organizations
Over 1000 organizations globally were hit with ransomware attacks during August, as the number of cyber extortion campaigns reached a new high for 2026, analysis of incidents has warned.
victims
973 organizations
The report stated the figure represented a record high for 2026 and a 12% increase on the 973 organizations hit by ransomware attacks during July.
threat_actor
INC Ransom
Some of the other most prolific ransomware groups during the reporting period were
Clop
(89 attributions), Dire Wolf (43) and INC Ransom (43).
In April this year, 'INC Ransom' directly attacked Jeju Bank, which demanded ransom during the process.
organisation
Moody
Over the last few weeks, however, The Gentlemen has started adding MIP's clients to its data leak site in a bid to get a ransom out of them, too,” Moody said.
organisation
MIP Holdings
“A prime example is The Gentlemen's recent attack on MIP Holdings (a South African tech company).
data_breach
201 GB
Stadler refused to pay the demand and Everest proceeded to leak 201 GB of stolen data.
financial
$2.3 Stolen / Extorted Funds
This was followed by Rhysida demanding $2.3m from the State of Berlin after compromising the authority’s network.
data_breach
5.7 TB
The group subsequently
published 5.7 TB
of stolen data, including personal information of citizens, after the state government publicly refused to pay.
organisation
IP
Limitations in tracing IP addresses..
organisation
the National Assembly's
According to a report submitted by Song Eun-seok, a member of the National Assembly's Administrative Affairs Committee of the People Power Party, and from the Financial Supervisory Service, there have been 18 overseas hacking incidents involving financial institutions since 2024, until this month.
organisation
Administrative Affairs Committee
According to a report submitted by Song Eun-seok, a member of the National Assembly's Administrative Affairs Committee of the People Power Party, and from the Financial Supervisory Service, there have been 18 overseas hacking incidents involving financial institutions since 2024, until this month.
organisation
the People Power Party
According to a report submitted by Song Eun-seok, a member of the National Assembly's Administrative Affairs Committee of the People Power Party, and from the Financial Supervisory Service, there have been 18 overseas hacking incidents involving financial institutions since 2024, until this month.
organisation
the Financial Supervisory Service
According to a report submitted by Song Eun-seok, a member of the National Assembly's Administrative Affairs Committee of the People Power Party, and from the Financial Supervisory Service, there have been 18 overseas hacking incidents involving financial institutions since 2024, until this month.
organisation
Jeju Bank
In April this year, 'INC Ransom' directly attacked Jeju Bank, which demanded ransom during the process.
organisation
The Financial Supervisory Commission
The Financial Supervisory Commission also stated that "it is practically impossible to identify the actual attacker based on overseas IP addresses alone.
organisation
OCS
Medical institutions operate multiple information systems, including electronic medical records (EMR), prescription delivery system (OCS), and medical image storage and transmission system, which are connected.
organisation
Download PDF
Download PDF
Data Source: Data Breaches Digest.
organisation
Flag Icons
Flag Icons created by
Freepik
and provided by
Flaticon
.
organisation
Flaticon
Flag Icons created by
Freepik
and provided by
Flaticon
.
the third quarter of 2026
Ransomware attacks reached their highest ever quarterly volume in the third quarter of 2026, according to Comparitech.
Click on any entity below to view its context and source!
organisation
Ransomware
Ransomware attacks reached their highest ever quarterly volume in the third quarter of 2026, according to an analysis by Comparitech.
organisation
Comparitech
Ransomware attacks reached their highest ever quarterly volume in the third quarter of 2026, according to an analysis by Comparitech.
Tactical Metrics
Metrics
financial
602,400
Financial Impact / Stolen Funds
Click for context!
The Comparitech report,
published
on October 7, found that the average ransomware demand in Q3 was $602,400.
Metrics
data_breach
201
Gb
Stadler refused to pay the demand and Everest proceeded to leak 201 GB of stolen data.
Metrics
financial
2,300,000
Stolen / Extorted Funds
This was followed by Rhysida demanding $2.3m from the State of Berlin after compromising the authority’s network.
Metrics
data_breach
6
Tb
The group subsequently
published 5.7 TB
of stolen data, including personal information of citizens, after the state government publicly refused to pay.
Metrics
victims
2,970,000
Customers
Last year, approximately 2,970,000 customers' information was leaked from Lotte Card and SC First Bank, which was suspected to be a Chinese attack.
Metrics
financial
179
Ransomware Victims
DBD discovered and researched
179 Ransomware Victims
over
50 Countries and Islands
claimed by
47 Data-Leaking Ransomware Operators
, including
3 Newly Discovered Ransomware Operators
last week.
Metrics
financial
47
Leaking Ransomware Operators
DBD discovered and researched
179 Ransomware Victims
over
50 Countries and Islands
claimed by
47 Data-Leaking Ransomware Operators
, including
3 Newly Discovered Ransomware Operators
last week.
Metrics
financial
3
Discovered Ransomware Operators
DBD discovered and researched
179 Ransomware Victims
over
50 Countries and Islands
claimed by
47 Data-Leaking Ransomware Operators
, including
3 Newly Discovered Ransomware Operators
last week.
Metrics
victims
1,000
Organizations
Over 1000 organizations globally were hit with ransomware attacks during August, as the number of cyber extortion campaigns reached a new high for 2026, analysis of incidents has warned.
Metrics
victims
973
Organizations
The report stated the figure represented a record high for 2026 and a 12% increase on the 973 organizations hit by ransomware attacks during July.
Intelligence Sources
Infosecurity-Magazine
2026-09-23
Ransomware Attacks Reach Record High for 2026
Infosecurity-Magazine
Infosecurity-Magazine
2026-10-09
Q3 2026 Sets New Record for Ransomware Attacks
Infosecurity-Magazine
DB Digest
2026-09-30
Dailysecu
2026-10-08
Chosun Economy
2026-10-09
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T12:18
Comprehensive Tactical Telemetry
Highly Correlated Entities
37x
organisation
Identified Entity
Ransomware
entity
28x
general metric
%
41
%
23x
timeline
Temporal Reference
Q3 2026
date
10x
target region
Target Country
United States
country
7x
industry
Targeted Sector
Finance
sector
5x
general metric
Incidents
16
incidents
4x
tactic
Cyber Operation Type
Ransomware
tactic
4x
attribution
Attributing Entity
the Health and Welfare Committee
authority
4x
general metric
Institutions
44
institutions
4x
target region
Target Region
EUROPE
region
3x
general metric
Comprehensive Hospitals
222
comprehensive hospitals
2x
general metric
Attacks
121
attacks
2x
threat actor
APT Group
ShinyHunters
actor
2x
general metric
Hours
64
hours
2x
general metric
Cases
2
cases
2x
victims
Organizations
1,000
organizations
Contextual Telemetry
Context Block
22 METRICS
general metric
Q3
247
q3
financial
Financial Impact / Stolen Funds
602,400
q3
malware
Malware Payload
Qilin
tool
data breach
Gb
201
gb
financial
Stolen / Extorted Funds
2,300,000
$
data breach
Tb
6
tb
source region
Origin Country
China
country
victims
Customers
2,970,000
customers
general metric
Overseas Hacking Incidents
18
overseas hacking incidents
general metric
Hacking Incidents
12
hacking incidents
general metric
Financial Companies
7
financial companies
general metric
Cyberattack
9
cyberattack
general metric
Remaining Incidents
11
remaining incidents
general metric
Reported Cyber Attacks
109
reported cyber attacks
general metric
Outpatient Hospitals
46
outpatient hospitals
general metric
Hospitals
822,600,000
hospitals
general metric
Won
58,700,000
won
financial
Ransomware Victims
179
ransomware victims
financial
Leaking Ransomware Operators
47
leaking ransomware operators
financial
Discovered Ransomware Operators
3
discovered ransomware operators
general metric
Attributions
89
attributions
general metric
Third %
31
third %
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.