Cybersecurity experts say FBI is investigating Ryuk ransomware attacks on more than two dozen US hospitals, and officials warned hospitals to back up systems
WASHINGTON (Reuters) - The FBI is investigating the recent targeting with ransomware of more than two dozen hospitals across …
Context & Ripple Effects
This October 2020 alert lands mid-campaign rather than at its start: Ryuk had already struck more than 235 US hospitals since 2018, collecting an estimated $100M in ransoms the year before, so the FBI investigation of a fresh cluster of two dozen-plus attacks is an escalation of a known pattern, not a new threat. The official guidance — back up your systems — is telling: with law enforcement unable to interdict the gang, resilience is being pushed down to individual hospital IT teams.
The story also previews how Washington would respond going forward. The FBI director would later describe tracking roughly 100 ransomware strains, many tracing back to Russia, as a challenge comparable to 9/11, and subsequent advisories — from the FBI-CISA-Treasury warning on North Korea's Maui ransomware in healthcare to the Prospect Medical Holdings investigation — show hospitals becoming a standing target set for both criminal and state-linked crews.
First-order effects
- More than two dozen US hospitals are operating under active ransomware attack while the FBI investigates, forcing them to weigh downtime against paying Ryuk for decryption.
- Federal officials' directive to back up systems shifts the immediate burden of defense onto hospital IT staff, making offline backups the difference between a recoverable incident and a shutdown.
Second-order effects
- Hospitals that restore from backups instead of paying undercut Ryuk's revenue model, pressuring the gang toward softer targets or higher demands on victims without resilient copies.
- Healthcare systems nationwide face pressure to fund segmentation, immutable backups, and incident planning, since the guidance effectively designates unprepared providers as the next victims.
Third-order effects
- If the pattern holds, hospitals become permanent critical-infrastructure targets for both criminal groups like Ryuk and state-backed crews — a trajectory confirmed by later advisories on Maui and Ghost ransomware hitting the sector.
- US cyber policy consolidates around a repeatable playbook — FBI investigation, CISA joint advisory, Treasury sanctions exposure — with resilience ('recovery by design') treated as the primary control when attribution and takedowns lag.
The trend: Ransomware is evolving from opportunistic extortion into sustained campaigns against critical infrastructure, with hospitals as a recurring target and federal agencies responding through investigations and joint advisories rather than prevention alone.