2 min read

MedLock Ransomware Targets Hospitals Across North America, Exploiting Legacy Medical Devices

A sophisticated new strain of ransomware has been detected targeting hospitals and healthcare networks across North America, raising urgent concerns among cybersecurity professionals and government agencies. Dubbed “MedLock,” the malware exploits vulnerabilities in legacy medical device software to gain initial access before spreading laterally through hospital networks.

How MedLock Operates

Security researchers first identified MedLock in late June 2026 after several mid-sized hospital systems reported simultaneous network outages. Unlike conventional ransomware that relies on phishing emails, MedLock takes advantage of unpatched DICOM (Digital Imaging and Communications in Medicine) servers, which are widely used for storing and transmitting medical imaging data.

Once inside a network, the malware deploys a custom credential harvester that targets Active Directory environments. Within hours of initial compromise, MedLock can encrypt patient records, disable backup systems, and lock out administrative accounts. The attackers demand payment in Monero, a privacy-focused cryptocurrency that is harder to trace than Bitcoin.

The Scale of the Threat

According to the Cybersecurity and Infrastructure Security Agency (CISA), at least 14 healthcare organizations have been affected since May 2026. The agency issued an emergency advisory urging all healthcare providers to audit their DICOM server configurations and apply available patches immediately.

“Healthcare remains one of the most vulnerable sectors because of the prevalence of legacy systems that cannot be easily updated,” said a CISA spokesperson. “Threat actors know this and are deliberately targeting these weak points.”

Patient Safety at Risk

The implications extend beyond data loss. In at least three confirmed cases, MedLock disruptions forced hospitals to divert emergency patients to other facilities. Medical professionals have warned that ransomware attacks on healthcare infrastructure can directly endanger lives when critical systems go offline during patient care.

Industry Response

Major cybersecurity firms including CrowdStrike, Mandiant, and Palo Alto Networks have released detection signatures and indicators of compromise (IOCs) for MedLock. The Health Information Sharing and Analysis Center (H-ISAC) has also distributed threat intelligence bulletins to its members.

Several cybersecurity vendors are now offering pro bono incident response services to affected hospitals, recognizing the critical nature of the threat. Meanwhile, lawmakers on Capitol Hill have renewed calls for mandatory cybersecurity standards in the healthcare sector.

Defensive Recommendations

Experts recommend that healthcare organizations take immediate steps to harden their defenses. These include segmenting networks to isolate medical devices, implementing multi-factor authentication across all administrative accounts, maintaining offline backups, and conducting tabletop exercises to test incident response plans.

As ransomware groups continue to evolve their tactics, the healthcare sector faces a critical window to shore up its cyber defenses before the next wave of attacks arrives.


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.