Threat actors are using AI to accelerate attacks on hospital virtual private networks, reviving a tactic first deployed during the COVID-19 pandemic, according to a Wall Street Journal report highlighted by trade press this week.
AI now lets attackers craft more convincing phishing emails, scan networks for vulnerabilities in minutes, and run credential-stuffing campaigns at scale, the Journal reported. Ram Varadarajan, CEO of cybersecurity firm Acalvio, told the publication that the shift makes it cheaper to walk through the front door than to storm the walls.
The threat is landing on a sector already under sustained pressure. Russia-based Qilin has racked up 168 confirmed healthcare-sector victims through June, trailing only manufacturing and business services in overall victim count, according to threat-intelligence firm Cyble. Qilin has repeatedly struck patient care organizations, and the group’s double extortion playbook pairs network encryption with stolen data leaks.
About a third of U.S. workers still split time between home and office, according to Bureau of Labor Statistics data, keeping VPNs a persistent gateway into hospital networks. For hospital IT leaders, VPN-targeted intrusions already rank among the most common entry points for ransomware groups, and AI is compressing the time attackers need to exploit them.
Hospitals should treat remote access as critical attack surface: enforce multifactor authentication on every VPN account, patch edge devices promptly, watch for unusual login patterns and credential stuffing, and segment clinical networks so a compromised gateway does not lead straight to the EHR.
