Attackers understand the calendar as well as payers do. At the beginning of Q4 2023, our researchers observed a spike in API attack traffic and an overall increase in activity during that period, a pattern that likely reflects attackers targeting open enrollment to disrupt operations when the cost of downtime is highest.
So while a DDoS attack in May is an inconvenience, the same attack during the enrollment window can stop members from selecting plans, disrupt claims operations, and inflict lasting brand damage at the worst possible moment.
That seasonal pressure sits within an already elevated healthcare threat environment. The Healthcare and Public Health sector reported 460 ransomware and 182 data breach complaints in 2025, the highest counts shown across the 16 critical infrastructure sectors.
Payers are particularly attractive targets because they hold both financial and clinical data. Healthcare records can fetch between US$250 and US$1,000 on the underground market, compared with an average of US$100 for credit cards. That value increases the incentive for credential stuffing, account takeover, and data theft during the exact period when login volume is at its peak.