Surprisingly Useful AI Article Enhancements
Stolen healthcare data is driving a growing underground cybercrime economy, with patient records becoming valuable criminal assets that persist for years and fuel identity theft, extortion and credential abuse across organised global networks.
Recent research examined 7,779 underground forum posts, 21,813 marketplace listings and 95 ransomware leak sites linked to healthcare-related cybercrime activity over a 12-month period. The study found that ransomware-related data sales accounted for 36.3 per cent of marketplace activity, as attackers increasingly combined data theft with encryption and extortion.
Patient records as long-term criminal assets
Takanori Nishiyama, Senior Vice President, APAC & Japan Country Manager at Keeper Security, pointed to the lasting value of healthcare data on criminal markets.
“This new research on stolen healthcare data reinforces a hard truth for cyber defenders across APAC: patient records have evolved into valuable criminal assets that the researchers say transcend geographic and language boundaries,” Nishiyama explained.
“A diagnosis, treatment history or biometric record cannot be cancelled and reissued like credit cards.”
He noted that healthcare records remain useful to criminals for extended periods, feeding into an organised market of access brokers, ransomware affiliates and fraud sellers.
“Healthcare records stay valuable for years, fueling identity theft, extortion and credential abuse across an organized market of access brokers, ransomware affiliates and fraud sellers around the world,” Nishiyama commented.
“These compromised credentials and exposed medical systems also allow cybercriminals to deploy ransomware and move laterally across hospital networks leading to follow-on attacks that further increase the damage. That permanence makes healthcare uniquely exposed.”
Australian healthcare under pressure
The threat is not abstract for Australian organisations. Ransomware incidents against Australian healthcare have doubled in recent years, and an increasing focus on electronic health record vendors means a single supplier compromise can spread across hundreds of providers sharing the same platform.
Nishiyama highlighted the structural challenges facing the sector.
“Healthcare environments combine high-value data, aging infrastructure, distributed third-party vendors and constrained budgets, creating conditions that traditional perimeter defenses were never built to contain,” he observed.
AI as a double-edged sword
The role of AI is adding complexity to the threat landscape, with both attackers and defenders adopting the technology.
“As both sides adopt AI in their toolkits, the risk intensifies,” Nishiyama warned. “Defenders gain faster detection and response times, while minimizing repetitive, time-consuming tasks. Meanwhile, attackers use AI to increase the speed and scale of their attacks.”
Zero-trust as a path forward
To address these risks, Nishiyama recommended a zero-trust security model with least-privileged access as a foundation for healthcare cybersecurity.
“Healthcare organizations should consider implementing a Privileged Access Management (PAM) solution to control, monitor and restrict access to critical systems and sensitive patient data,” he outlined.
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
“By securing privileged accounts, enabling real-time monitoring and enforcing role-based access controls, organizations reduce the risk of credential theft, privilege misuse and unauthorized access that leads to damaging breaches.”
He added that if an attack does occur, such measures help reduce the blast radius and limit the resulting damage.
“Effective security programs combine technology with ongoing user education and regular access audits to ensure that policies are consistently enforced and aligned with strict healthcare compliance requirements,” Nishiyama concluded.
Last Updated on June 20, 2026 by Nick Ross



