Held Hostage: How Ransomware Gangs Turned Hospitals, Schools, and Main Street Into Targets
Photo: ransomware attack hospital computer network security breach, via blogger.googleusercontent.com
There is a particular cruelty embedded in the logic of modern ransomware. Its operators deliberately seek out organizations where the cost of downtime is measured not merely in revenue but in human welfare — where a locked electronic health record system means a nurse cannot confirm a patient's medication dosage, where an encrypted school network means thousands of families learn their children's personal data has been stolen and published online. That calculus is not accidental. It is a business strategy.
The ransomware ecosystem has undergone a fundamental transformation over the past several years, and understanding its current architecture is essential for anyone responsible for defending an organization — or simply trying to make sense of why these attacks keep happening.
The Ransomware-as-a-Service Model: Crime with a Franchise Structure
The dominant operational model in today's ransomware landscape is ransomware-as-a-service, or RaaS. Under this arrangement, a core development group — sometimes numbering only a few dozen individuals — builds and maintains the malware, the encryption infrastructure, the victim negotiation portal, and the cryptocurrency payment system. They then recruit affiliates: other criminal actors who handle the actual intrusion work. Affiliates receive a share of each ransom payment, typically between 70 and 80 percent, while the core group collects the remainder.
This structure has proven remarkably resilient. When law enforcement dismantles a RaaS operation — as happened with LockBit in early 2024 — the affiliates disperse and attach themselves to competing platforms. The technical expertise and the criminal relationships persist even when the infrastructure is seized. It resembles, in some respects, the franchise model of legitimate business: the brand can be disrupted, but the operators find new flags to operate under.
The major RaaS groups active in recent years — LockBit, ALPHV/BlackCat, Cl0p, Play, and others — have demonstrated not only technical sophistication but also an ability to adapt their tactics in response to defensive measures and law-enforcement pressure.
Why Essential Services Became the Preferred Target
Early ransomware campaigns cast a wide net, infecting consumers and businesses indiscriminately. The shift toward critical infrastructure and essential services reflects a deliberate recalibration based on one variable: willingness to pay.
Hospitals cannot tolerate extended downtime. Patient care depends on immediate access to records, imaging systems, pharmacy databases, and communication networks. When those systems are encrypted, the pressure to restore operations quickly — and to do so without waiting weeks for forensic recovery — creates leverage that criminal operators exploit deliberately. The American Hospital Association has reported that ransomware attacks on healthcare facilities have led to diverted ambulances, postponed surgeries, and in documented cases, outcomes linked to delayed treatment.
School districts present a different but equally compelling target profile. They typically operate with lean IT staffing, aging infrastructure, and budgets that leave little room for enterprise-grade security tooling. They also hold extraordinarily sensitive data — Social Security numbers, behavioral health records, and financial information belonging to minors. The Cl0p group's exploitation of the MOVEit file-transfer vulnerability in 2023 compromised student records across dozens of American school districts, demonstrating how a single vulnerability in a widely used third-party tool can cascade across an entire sector.
Small businesses occupy a particularly vulnerable position. They lack the resources of large enterprises but face the same threat landscape. A ransomware event that a Fortune 500 company absorbs as a costly disruption can permanently close a small manufacturer, a regional law firm, or an independent medical practice. The FBI's Internet Crime Complaint Center consistently reports that small and medium-sized businesses account for a disproportionate share of ransomware victims.
The Geopolitical Dimension
Ransomware is not purely a criminal phenomenon. Several of the most prolific groups operate from jurisdictions — Russia, North Korea, Iran — where governments either tolerate their activity, actively protect their operators, or in some cases direct their targeting. North Korean state-affiliated actors have used ransomware and cryptocurrency theft to generate hard currency in defiance of international sanctions. Russian-nexus groups have historically avoided targeting organizations within the Commonwealth of Independent States, a pattern that suggests implicit coordination with state interests.
This geopolitical dimension complicates the law-enforcement response. Indictments issued by the Department of Justice carry significant symbolic weight and can complicate the travel and financial activity of named defendants, but they cannot compel extradition from non-cooperative states. Sanctions designations issued by the Treasury Department's Office of Foreign Assets Control add another layer of pressure — and create legal exposure for any organization that pays a ransom to a designated entity — but they do not neutralize the threat.
Case Studies in Consequence
The 2021 attack on Colonial Pipeline remains one of the most instructive examples of how ransomware can reverberate through civilian infrastructure. The DarkSide affiliate group's intrusion forced a precautionary shutdown of pipeline operations supplying approximately 45 percent of the East Coast's fuel. Gas shortages materialized within days. Colonial paid approximately $4.4 million in ransom; the Department of Justice subsequently recovered a portion of the payment by seizing a cryptocurrency wallet.
More recently, the February 2024 attack on Change Healthcare — a subsidiary of UnitedHealth Group that processes a significant share of American prescription claims — disrupted pharmacy operations nationwide for weeks. Hospitals and independent pharmacies were unable to process insurance claims, and some smaller providers reported acute cash-flow crises as a direct result. The ALPHV/BlackCat group claimed responsibility before its infrastructure was disrupted by law enforcement; the ransom reportedly paid was in the range of $22 million.
These cases illustrate that the downstream effects of a single ransomware event can extend far beyond the directly targeted organization.
What Organizations and Individuals Can Do
Defense against ransomware is achievable, but it requires consistency across several domains.
Maintain tested, offline backups. The most effective single control against ransomware's leverage is a recent backup that cannot be reached by the same network intrusion that encrypts production systems. Backups stored exclusively on network-attached devices are frequently encrypted alongside primary systems. Offline or immutable backups fundamentally alter the calculus of whether to pay.
Patch aggressively and prioritize internet-facing systems. A substantial proportion of ransomware intrusions begin with the exploitation of known, patched vulnerabilities in VPN appliances, remote desktop services, and file-transfer platforms. Organizations that maintain current patch levels on externally accessible systems eliminate a significant share of the available attack surface.
Segment networks. Flat network architectures allow ransomware to propagate laterally without restriction. Network segmentation limits the blast radius of a successful intrusion, containing damage to a subset of systems rather than the entire environment.
Enforce multi-factor authentication on all remote access. Credential theft and purchase of stolen credentials on criminal marketplaces is a primary initial-access vector. MFA on VPN, remote desktop, and cloud administrative accounts substantially raises the cost of exploitation.
Develop and rehearse an incident response plan. Organizations that have never simulated a ransomware event before experiencing one make slower, more costly decisions under pressure. Tabletop exercises that walk through the first 72 hours of a ransomware response — including who has authority to make decisions, when to engage law enforcement, and how to communicate with stakeholders — produce measurably better outcomes.
For individuals, the most meaningful contribution is awareness of phishing, which remains the most common initial-access vector. Ransomware does not typically arrive as a sophisticated zero-day exploit; it arrives as a malicious email attachment opened by a person who did not recognize the risk.
The Outlook
Ransomware volume and sophistication show no credible signs of decline. The criminal economics remain favorable, the geopolitical sanctuaries remain largely intact, and the pool of under-defended targets remains vast. What has changed is the quality and breadth of available guidance — from CISA's known exploited vulnerabilities catalog to sector-specific advisories from the HHS and the Department of Education — and the growing recognition among policymakers that ransomware is a national security issue, not merely a cybercrime statistic.
Organizations that treat security investment as a cost center rather than a risk-management function will continue to learn that lesson the hard way. Those that act on the available guidance before an incident arrives will find themselves in a considerably stronger position when — not if — they are targeted.