Skip to content

LockBit 4.0 Ransomware Campaign Targeting Healthcare Sector

Posted on:January 20, 2026 at 02:00 PM

TLDR: LockBit 4.0 affiliates have launched coordinated attacks against healthcare providers, exploiting unpatched VPN appliances as initial access vectors. Over 30 organizations reported incidents in the past week.

The campaign leverages known vulnerabilities in Fortinet and Cisco VPN products. Threat actors are demanding ransoms between $500K-$5M, with patient data exfiltration as additional leverage.

Indicators of Compromise: