Health Data, Workforce Development, Privacy and Security
AI Agents Are Changing Ransomware Attacks on Healthcare Organizations
In just a few years, generative artificial intelligence (AI) has been making familiar forms of cybercrime faster, cheaper, and easier to scale. Attackers now use generative AI to do everything from reconnaissance and researching vulnerabilities to drafting convincing phishing emails to generating malicious code at great speed. But a new frontier is emerging: AI agents capable of autonomously executing complex attack sequences with minimal human oversight, or even none at all.
Agentic AI attacks may seem like a distant possibility, but we’re already starting to see AI act independently. Consider the recent incident where an OpenAI test model escaped its test environment and hacked into another company's servers. The evaluation was being conducted with normal production safety measures disabled, but the incident nevertheless offered a concrete demonstration of an AI system chaining together exploitation, credential theft, privilege escalation, and lateral movement with limited human direction.
The implications for ransomware are significant. As these capabilities mature, AI agents could plan and launch their own attacks at an unprecedented scale. We’re facing a future where ransomware operations may become faster, more numerous, and increasingly difficult for defenders to detect and contain.
For healthcare organizations, which already have low tolerance for downtime, this doesn’t bode well. A 2022 study found that 44.4 percent of identified healthcare ransomware attacks disrupted care delivery, including downtime in electronic records, canceled care, and ambulance diversions. Among patients already admitted to the hospital during a ransomware attack, a 2026 American Economic Journal study found that in-hospital mortality increased by 34–38 percent.
At scale, ransomware goes from data theft to posing a direct threat to life when labs, health record systems, imaging, and scheduling are taken down or held hostage.
From AI-assisted to Agentic Ransomware
Ransomware operators and other threat actors are already using AI to accelerate parts of their operations including reconnaissance, phishing, vulnerability research and coding, according to the UK National Cyber Security Centre. Cybercriminal gangs are leveraging AI to speed up the most labor-intensive work in social engineering by automatically and iteratively testing what kinds of messaging may work best against a target and even charting out convincing follow-up conversations with potential victims.
The bar for both expertise and labor has fallen, which is allowing hackers to continuously improve their campaigns at great speed and scale.
For healthcare organizations, where even a single vulnerability can provide a pathway to systems that are critical for patient care, this reality mandates a new strategy for defense: move beyond the traditional security system built around preventions at the network perimeter.
As AI enables attackers to move faster, defenders must assume that some threats will evade initial defenses. Success for the health sector will increasingly depend on mitigation.
Building Organizational Resilience
As AI enables attackers to rapidly move through each layer of security, defense strategies must focus on improving their time to detection, containment, and recovery.
As defenders, we have to accept the fact that autonomous attackers are good at obtaining credentials and moving laterally through the network. Limiting what attackers can do after initial access is often more effective than attempting to stop every intrusion at the network’s edge. Focus on limiting access by treating user and machine identities as the core security perimeter. Assume every network connection is unsafe, give accounts only the permissions they need to operate, and validate active sessions continuously.
Healthcare professionals should identify the systems whose disruption would have the greatest impact on patient care — such as electronic health records, laboratory information systems, and imaging platforms. Ensure each has a tested recovery plan with established downtime procedures. Implement multifactor authentication, least-privilege access, and continuous monitoring for abnormal login activity to reduce an attacker's ability to reach critical assets such as clinical systems.
Offline or immutable backups should be regularly validated through restoration exercises rather than assumed to work.
To match the speed of this threat, organizations should automate parts of their own defense. Behavioral analytics can identify subtle indicators of compromised systems, such as unusual authentication patterns, privilege escalation, or lateral movement, while automated detection and response tools can isolate compromised devices, revoke sessions, or suspend compromised credentials before ransomware moves further across the network.
Collective Defense Is Key
The only realistic way to get ahead of this threat is to reduce the time between detection and containment. The first part of that problem can be tackled through collaboration and information-sharing with peer organizations.
Collective defense has long been one of the cybersecurity industry’s greatest advantages, and today it’s even more valuable. A hospital seeing the first signs of an attack may have only a partial picture, but when those observations are quickly shared across the sector, they become an early warning for everyone else.
Sector-specific information sharing can be a force multiplier. Share suspicious domains, phishing themes, attacker infrastructure, malware hashes, VPN scanning activity, or novel tactics to allow your peers to seek out the same indicators and build defenses. One institution’s telemetry can become another institution’s early warning system.
Prepare for the Next Evolution
Agentic ransomware is not the threat of a hypothetical future from science fiction. The capabilities described in this article already exist today, and attackers are steadily combining them to build increasingly autonomous operations.
Healthcare organizations shouldn’t wait to adapt their defenses. The question is no longer a matter of if an attack will occur, but when.
As ransomware operations become increasingly autonomous, organizations that share cyber threat intelligence in real time will be better positioned to disrupt campaigns before they cascade across the ecosystem.
Errol S. Weiss is Chief Security Officer of Health-ISAC.