• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage
  • Life Sciences
  • Research

2023’s Biggest Pharma Cybersecurity Threats to Watch

by JP Perez-Etchegoyen, CTO of Onapsis 02/03/2023 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print
2023’s Biggest Pharma Threats to Watch
JP Perez-Etchegoyen, CTO of Onapsis

Due to the recent growth of the pharmaceutical industry, the value of highly-sensitive data stored in pharmaceutical systems and the degree of the potential damage that cyberattacks on the industry can cause, it is safe to say that pharma could be one of the most targeted industries by cybercriminals in 2023. Ransomware, phishing attacks, business applications and third-party vendors will be some of the biggest threats to this key vertical as we approach the new year.

Ransomware
The threat of ransomware is nothing new, but cybercriminal tactics surrounding ransomware continue to evolve, making the pharma industry susceptible to these kinds of attacks now more than ever. With the ongoing COVID-19 pandemic, ransomware groups’ attraction to pharma and life sciences organizations is at an all-time high with classified information, research and vaccines stored in these systems – we have seen targeted attacks in this sector over the last few years with REvil/Sodinokibi, Egregor and Conti. In 2021, there was a 44% spike in cybercrime within healthcare organizations. 

Double extortion, a tactic that involves combining high ransom demands with the threat of making private information available to the public, is becoming a popular technique for ransomware groups. Attackers are able to find the best places to encrypt systems during an attack by lurking in a target’s network for some time, completely undetected. Ransomware tactics are increasingly successful in extracting sizable payments from unwitting victims at a time when trust is essential to any organization’s reputation and performance.

Phishing Attacks
The number of phishing attacks targeting the pharmaceutical industry between December 2020 and February 2021 increased by 189%— during this same time period, there was a 530% increase in phishing attacks specifically related to vaccines. Threat actors were able to create fake websites pretending to be pharma companies offering COVID-19 vaccines, and then steal credentials when users attempted to sign in. Unfortunately, pharma organizations involved in developing COVID-19 vaccines, and vaccines in general, continue to be hot targets for cybercriminals. As the COVID-19 pandemic continues, and as new cases are reported every day and new booster shots roll out, we can expect these targeted attacks on pharma organizations offering vaccines to continue.

Business Applications
With the increases in attacks on business applications highlighted by the latest technical alerts, as well as current activity alerts from CISA and the shift in focus toward the pharma industry by threat actors, there is a weak spot that threat actors will continue targeting in 2023 – business-critical applications. These applications are vital to keeping pharma industry operations up and running properly and have been consistently overlooked from a security standpoint.

Third-Party Vendors
Third-party vendors providing critical services to pharmaceutical organizations are low-hanging fruit to cybercriminals looking for an easy win. While most internal systems of pharma organizations themselves are secure and equipped with robust cybersecurity measures to keep these cybercriminals out, it is likely that outsourced vendors for services like sales, IT and reporting are not as well-equipped – over half of 2021’s data breaches were connected to third-party vendors.

With the average cost of a data breach in the pharmaceutical industry surpassing $10 million in 2022, it has become the most costly data breach across all industries and sectors, and when the breach involves a third-party vendor, these costs increase significantly.

The pharmaceutical industry houses some of the most valuable data and technology in our world, which places a massive target on this industry’s back when it comes to malicious cybercriminals. Not only is patient data a hot target for these criminals, but advances in technology, drugs, clinical trials and other highly-sensitive research projects are also accessed through these same systems that continue to be preyed upon. In order to secure databases in the industries that are most critical to our quality of life, organizations must familiarize themselves with the biggest potential threats heading into the new year and how to protect themselves – through robust cybersecurity controls and trusted partners.


About JP Perez-Etchegoyen

As CTO, JP leads the innovation team that keeps Onapsis on the cutting edge of the Business-Critical Application Security market, addressing some of the most complex problems that organizations are currently facing while managing and securing their ERP landscapes. JP helps manage the development of new products as well as support the ERP cybersecurity research efforts that have garnered critical acclaim for the Onapsis Research Labs.

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tagged With: Clinical Trials, Cybercriminals, Cybersecurity, Life Sciences, Partners, Pharma, Phishing, Vital

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Featured Insights

 Selecting the Right EMR: A Practical Guide to Streamlining Your Practice and Enhancing Patient Care

Selecting the Right EMR: A Practical Guide to Streamlining Your Practice and Enhancing Patient Care

Featured Interview

Virta Health CEO: GLP-1s Didn’t Kill Weight Watchers, Its Broken Model Did

Most-Read

Health IT Sector Navigates Policy Turbulence with Resilient M&A

Health IT’s New Chapter: IPOs Return, Resilient M&A, Valuations Rise in 1H 2025

PwC Report: US Medical Cost Trend to Remain Elevated at 8.5% in 2026

PwC Report: US Medical Cost Trend to Remain Elevated at 8.5% in 2026

Philips Launches ECG AI Marketplace, Partnering with Anumana to Enhance Cardiac Care with AI-Powered Diagnostics

Philips Launches ECG AI Marketplace, Partnering with Anumana to Enhance Cardiac Care with AI-Powered Diagnostics

WeightWatchers Emerges from Bankruptcy, Launches New Menopause Program

WeightWatchers Emerges from Bankruptcy, Launches New Menopause Program

CMS Finalizes New Interoperability and Prior Authorization Rule

CMS Proposes 2026 Physician Fee Schedule Rule: Boosting Primary Care, Cutting Waste, and Modernizing Payments

Beyond SaaS: How Agent as a Service is Transforming Healthcare Automation

Beyond SaaS: How Agent as a Service is Transforming Healthcare Automation

New Strategies Needed: No Surprises Act and the Challenges for Payors with Provider Data Inaccuracies

Samsung Acquires Xealth to Accelerate Connected Care Vision

Samsung Acquires Xealth to Accelerate Connected Care Vision

AI Dominates Digital Health Investment in First Half of 2025

Rock Health Report: AI Dominates Digital Health Investment in First Half of 2025

Moving Beyond EHRs: What Lies Ahead for Healthcare Digitization?

AI Agents vs. Chatbots: Understanding Agentic AI’s Role in Healthcare

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • Submit An Op-Ed
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2025. HIT Consultant Media. All Rights Reserved. Privacy Policy |