< Back to all clusters
[CRIME] · United States, Netherlands, India · 17 sources

Ransomware extortion spikes and AI‑generated phishing invoices target Dutch healthcare

Ransomware operators are increasingly using repeat‑extortion tactics. Proofpoint’s 2026 AI‑Era Ransomware Report found that more than one‑third of organisations that paid a ransom received a second demand, and 37 % of victims faced repeat extortion. The study also noted that AI‑enhanced phishing, impersonation and credential theft made attacks more effective, with 65 % of respondents saying AI improved ransomware success. Sophos reported that average recovery costs rose 11 % to $1.7 million even as median ransom payments fell 62 %.

In the United States, Cyble tracked 1,721 ransomware attacks in the first half of 2026 – roughly 45 % of the world’s total incidents – with professional services, construction and healthcare most targeted. In India, 62 % of ransomware victims said AI increased attack effectiveness, and 48 % of those who paid were hit again.

At the same time, Infomedics, which processes the majority of Dutch dental and other health‑care invoices, warned of a record surge in phishing emails containing AI‑generated fake invoices. More than 20 000 reports of fraudulent “care‑bill” emails were logged in 2026, up from just dozens the previous year. Criminal networks operating from India, Romania and Peru use generative AI tools to create convincing invoices worth €100‑€160, often mimicking Infomedics’ official sender address. The company urges recipients to verify any email that deviates from its standard [email protected] address.

Sources

1 day ago
about 13 hours ago
about 23 hours ago
about 17 hours ago