FIN12 is a financially motivated intrusion group known for moving quickly from access to ransomware deployment and for targeting large organizations. Mandiant tracked it from at least October 2018 and reported that it often relied on other actors for initial access. Its observed victims included many healthcare organizations, and the ransomware brands associated with its operations changed over time.
What is FIN12?
Mandiant described FIN12 as an aggressive, financially motivated threat actor behind ransomware attacks since at least October 2018. It is best understood as an intrusion operator specializing in ransomware deployment—not as a single, permanent ransomware product. Mandiant reported that FIN12 commonly depended on other actors for initial access, so the group’s activity could involve relationships with access providers as well as the people deploying ransomware.
That distinction matters when interpreting a ransomware incident: a brand name found in an attack does not necessarily identify every actor involved, and a group’s methods or partnerships can persist even as the ransomware brand changes.
How quickly did FIN12 deploy ransomware?
Mandiant’s time-to-ransom (TTR) measures the time between initial access and ransomware deployment. In its October 7, 2021 summary, Mandiant said FIN12 cut its TTR in half compared with 2020, reaching 2.5 days in the first half of 2021. That is a historical finding for the period Mandiant analyzed, not a guarantee that every FIN12 incident followed the same timeline.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
| Observed case or period | Reported time-to-ransom | Qualification |
|---|---|---|
| FIN12, first half of 2021 | 2.5 days | Mandiant said this was half the 2020 level; reported October 7, 2021. |
| Incidents where data theft was observed | Just under 12.5 days on average | Mandiant’s detailed profile; average for the incidents in which theft occurred. |
| Incidents where data theft was not observed | 2.5 days on average | Mandiant’s detailed profile; average for the incidents in which theft was not observed. |
The longer average in incidents involving observed data theft does not establish that theft itself caused a delay. It does show why defenders should not assume ransomware deployment is always the first visible sign of an intrusion—or that an apparently rapid attack rules out data theft.
Why did FIN12 target large companies?
Mandiant’s victim profile shows a pronounced focus on large organizations: the vast majority of known victims had annual revenue above $300 million. The same profile reports average annual revenue above $6 billion among observed victims, but cautions that visibility limits and outliers may skew that average. These figures describe Mandiant’s observed victim set; they are not a rule that every target had those revenues.
The evidence establishes that FIN12 disproportionately affected large organizations, but it does not prove a single reason for selecting them. FIN12 was financially motivated, and its victim profile is consistent with an operator pursuing substantial ransom opportunities. That is a reasonable interpretation of the pattern, not a documented statement of the group’s internal decision-making.
Did FIN12 target hospitals and other healthcare organizations?
Yes. Nearly 20% of FIN12 victims directly observed by Mandiant were healthcare organizations. That makes healthcare a significant part of the group’s documented victim profile, though not the only one. Other affected sectors included business services, education, finance, government, manufacturing, retail, and technology.
Rank #3
The percentage refers to directly observed victims, not every FIN12 victim worldwide. It should not be read as a current rate or as a prediction about the share of future attacks.
Where were FIN12’s victims?
FIN12’s observed victims were initially concentrated in North America. Mandiant’s detailed profile placed approximately 71% in the United States and 12% in Canada. Mandiant also documented activity affecting organizations in Australia, Colombia, France, Indonesia, Ireland, the Philippines, South Korea, Spain, the United Arab Emirates, and the United Kingdom.
Rank #4
The country percentages describe the victim profile in that report, while the additional countries show that the group’s documented reach was not limited to North America. They do not establish the group’s present-day geographic distribution.
Which ransomware families have been linked to FIN12?
FIN12’s reported brand affiliations changed. CERT-FR reported use of Ryuk and Conti between 2020 and 2023, followed by participation in Hive, BlackCat, Nokoyawa, Play, and Royal programs. These associations are evidence of evolving ransomware relationships, not proof that FIN12 created or exclusively operated each family.
Best Value
For attribution, the practical lesson is to consider the operator’s behavior and access relationships alongside the ransomware name. A brand can change while an intrusion group’s role or partnerships continue to evolve.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What can organizations do to reduce risk?
FIN12’s reported reliance on partner actors for initial access and its short time-to-ransom make early detection and a rehearsed response especially relevant. The following measures are defensive recommendations based on that operating pattern; no single control guarantees prevention.
Quick Recap
- Detect and contain quickly: use managed detection and endpoint monitoring to investigate suspicious identity, endpoint, and network activity before it escalates to encryption.
- Harden identity and endpoints: restrict privileged access, strengthen authentication, keep endpoint defenses maintained, and investigate unusual account or device behavior.
- Limit lateral movement: segment networks and restrict unnecessary access between systems, especially around sensitive services and backup infrastructure.
- Prepare recoverable backups: maintain offline or immutable copies and test restoration, rather than assuming that backup files will be usable during an incident.
- Practice incident response: rehearse rapid decision-making, containment, recovery, and communications so responders can act under a compressed timeline. Ransomware incident-response training and an enterprise ransomware preparedness review can help identify gaps.
- Assess threat intelligence in context: use a threat-intelligence assessment to understand relevant access relationships and behaviors, rather than relying only on a list of ransomware brand names.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

