🛡️ Cybersecurity / /via Reuters / updated 2d ago

CrowdStrike Identifies July 15 Ransomware Attack on 12000 Healthcare Endpoints

CrowdStrike detected a ransomware campaign on July 15 2026 that encrypted data on 12000 healthcare endpoints across 47 hospitals. The attack used a previously unknown loader targeting unpatched Windows systems. No patient data exfiltration has been confirmed as of July 19 2026.

#CrowdStrike
~/ Cybersecurity/ CrowdStrike Identifies July 15 Ransomware Attac...

CrowdStrike detected a ransomware campaign on July 15 2026 that encrypted data on 12000 healthcare endpoints across 47 hospitals. The attack leveraged a zero-day loader targeting Windows systems missing patches released in May 2026. Affected organizations include regional hospital networks in Texas and Florida.

The ransomware demanded 8 million dollars in Bitcoin within 72 hours. CrowdStrike released signatures and behavioral detections on July 16 2026 at 03:14 UTC. Hospitals restored operations using offline backups within 48 hours in 39 of the 47 cases.

This incident follows a series of healthcare-targeted attacks in 2026 that prompted the Department of Health and Human Services to issue new cybersecurity guidelines on June 1 2026. CrowdStrike attributes the campaign to a financially motivated group previously observed in European manufacturing attacks. The loader exploited a vulnerability in a third-party remote monitoring tool.

Healthcare organizations have increased security spending by 28 percent year-over-year according to a HIMSS survey published in May 2026. CrowdStrike noted that 62 percent of affected endpoints lacked the May 2026 security update. The company is assisting the FBI with attribution analysis.

Why this matters

Healthcare remains the most targeted vertical for ransomware in 2026 with average downtime costs exceeding 1.2 million dollars per day. The July 15 attack demonstrates continued success of living-off-the-land techniques against critical infrastructure. Regulators are expected to mandate faster patch deployment timelines for medical device networks.

Hospital IT teams have accelerated migration to cloud-hosted electronic health record systems following this incident. CrowdStrike reported a 45 percent increase in healthcare customer inquiries within 48 hours of disclosure. Insurance premiums for cyber coverage in the sector rose 19 percent in the past quarter.

The FBI issued a flash alert on July 18 2026 recommending immediate isolation of legacy Windows servers. No ransom payments have been confirmed as of July 19 2026.

share
𝕏 FB
← cd ../news