Surge in cyberattacks on local health authorities and hospitals, citizens’ data at risk and systems in disarray

The healthcare sector is increasingly in the crosshairs of cybercriminals, with cyberattacks against healthcare facilities rising at an alarming rate. The figures speak for themselves: incidents targeting hospitals and healthcare organisations have risen sharply, with a 111 per cent increase, rising from 27 incidents in 2023 to 57 in 2024, according to official data from the National Cybersecurity Agency. And according to Energieering, a company specialising in the cybersecurity of critical infrastructure, the trend shows no sign of reversing, with around 84 attacks (+47.4%) forecast for 2025 and an estimated 124 for 2026. That amounts to practically one attack on the healthcare sector every three days.

Beyond the economic impact – according to IBM’s *Cost of a Data Breach 2025* report, each data breach in the healthcare sector costs an average of 7.42 million dollars – these attacks represent one of the greatest challenges facing the healthcare system, posing a risk to citizens’ health: data breaches can, in fact, cause problems such as the paralysis of the Central Appointments Service (CUP), the loss of test records or even difficulties in the distribution of blood to operating theatres.

“The reality of the situation,” confirms Massimo Dutto, head of IT for the healthcare sector at the certification body CSQA, “is that these attacks will continue to increase. The risks are no longer limited to data theft, but also include the disruption of business continuity.” Founded in 1990, CSQA now has a network of 500 auditors operating in 31 countries and over 680 active certifications in cybersecurity and data protection. Healthcare facilities are usually targeted by organisations acting with the aim of obtaining, in exchange for the return of the compromised system, a payment in cash or, more often, in cryptocurrencies, which are more difficult to trace. Public sector organisations, however, as Dutto explains, usually ‘do not pay a ransom, as this would be tantamount to guaranteeing a subsequent breach’.

When discussing cyber-attacks on healthcare facilities, according to the head of IT for the healthcare sector at CSQA, a distinction must first be made. If, when attacking a hospital, a hacker confines themselves to stealing staff data, then this constitutes a data breach relating to privacy, which, however, has no impact on citizens’ health. If, on the other hand, upon gaining access to the system, the hacker blocks and steals everything they find, patient data – such as their medical history or their identification number relating to the treatment they are undergoing in hospital – is also stolen. ‘An increased likelihood of cyber-attacks on healthcare facilities therefore poses a threat to citizens’ health, paralysing the system and causing it to crash. It has been recognised internationally that this is a very real risk,’ explains Dutto.

Although it is not possible for hospitals to completely eliminate the danger, ‘we can work to reduce it. We must ensure that the risk is low, whilst remaining aware that the possibility of infection entering these facilities still exists and is primarily driven by people’s behaviour. What we can do as a certification body is to carry out an assessment to evaluate the system’s vulnerability, checking that all necessary countermeasures have been put in place to minimise damage’.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *