Brazil Leads Ransomware Attacks on Health Care
Santotech says Brazil accounts for most Latin American ransomware attacks on health care, driven by phishing and outdated medical systems.
Brazil accounts for the largest number of ransomware attacks targeting the health care sector in Latin America, according to a Santotech article that does not identify threat groups or specific cases.
Brazil accounts for the largest number of ransomware attacks targeting the health care sector in Latin America, according to a Santotech article that does not identify threat groups or specific cases.
Tactics cited
The publication describes generic TTPs, including phishing, exploitation of vulnerabilities in outdated medical systems and equipment, and disruption of critical hospital systems to increase pressure on victims and force ransom payments.
Repeated weaknesses in hospitals
Santotech also says that Brazilian hospitals affected by ransomware in Latin America often show network segmentation failures, a lack of multifactor authentication on privileged accounts, and no incident response plans. According to that description, those gaps magnify the operational impact of attacks once they gain access to the network.
The combination of initial access through phishing, exposed unpatched medical equipment and environments with weak access controls leaves health care providers with less ability to contain and recover. In that context, disruption of critical systems affects not only continuity of care, but also reinforces ransomware's extortion goal.
At the same time, Brazil's National Data Protection Authority, known as the ANPD, said it had opened a sanctioning process against a social organization over a data protection failure involving 500,000 patients at public health units, a development that again puts the country's health care security practices under scrutiny.
Sources
- Brasil concentra maior número de ataques de ransomware ao setor de saúde na América Latinasantotech.com.br· Santotech
- ANPD instaura processo de sanção contra OS por falha na proteção de dados de 500 mil pacientesgov.br· ANPD (gov.br)



