Healthcare threat intelligence report — 27 April – 3 May 2026
The healthcare threat picture for the reporting period continues to escalate. Health-ISAC reporting flags a 55% surge in cyber incidents in 2025 with continued escalation expected in 2026.
- Reference: TI-2026-0504-005 (public edition)
- Sector: Healthcare
- Reporting period: 27 April – 3 May 2026
- Issued: 4 May 2026 · Lead analyst: P. Bassill (SOC Lead) · Reviewed by: SOC Reviewing Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The healthcare threat picture for the reporting period continues to escalate. Health-ISAC reporting flags a 55% surge in cyber incidents in 2025 with continued escalation expected in 2026. Comparitech recorded 201 healthcare ransomware attacks in Q1 2026 — 120 against direct providers and 81 against sector-adjacent businesses. Qilin, INC Ransom and SAFEPAY are the dominant ransomware operators against the vertical, with Qilin behind the most confirmed provider attacks during the reporting period. The University of Mississippi Medical Center (Feb 2026, US) and Nippon Medical School Musashi Kosugi Hospital (Feb 2026, Japan, 131,700 records) remain the headline-case studies.
Key Judgements
1. It is highly likely that ransomware will remain the principal material-risk scenario for the healthcare vertical over the next reporting cycle, with Qilin, INC Ransom and SAFEPAY the most operationally-relevant operators. (HIGH confidence)
2. It is highly likely that VPN- and edge-appliance-exploitation will continue to be the dominant initial-access vector against healthcare providers, with Citrix NetScaler CVE-2026-3055 / 4368 the immediate concern. (HIGH confidence)
3. It is likely that AI-enabled ransomware tradecraft — particularly automated phishing and reconnaissance — will materially increase the operational tempo of healthcare-targeted campaigns through the rest of 2026. (MEDIUM-HIGH confidence)
4. There is a realistic possibility that a UK NHS Trust or material UK healthcare provider will suffer a multi-day operational outage from ransomware within the next six reporting cycles. (MEDIUM confidence)
2. Sector threat landscape
The healthcare vertical absorbed a 55 per cent surge in cyber incidents through 2025 according to Health-ISAC, with continued escalation expected through 2026. Comparitech recorded 201 healthcare ransomware attacks in Q1 2026 alone — 120 against direct providers (hospitals, clinics, group practices) and 81 against sector-adjacent businesses (pharmaceutical, medical-device, payer). The trajectory has not flattened during the April-May 2026 reporting period.
The dominant ransomware operators against the vertical during the reporting period are Qilin, INC Ransom and SAFEPAY. Qilin retains the leading position with 103 leak-site postings in April 2026 and was behind the most confirmed direct-provider attacks during the same period. INC Ransom continues to favour the public-sector-and-healthcare lane, and SAFEPAY has emerged as a high-tempo follow-on actor. LockBit and TheGentlemen each posted three confirmed healthcare-provider incidents during the reporting period.
The headline-case studies remain the University of Mississippi Medical Center incident of February 2026 (US, multi-clinic operational shutdown) and Nippon Medical School Musashi Kosugi Hospital incident of February 2026 (Japan, NetRunner attribution, 131,700 individuals impacted). The H-ISAC Heartbeat reporting flags a sustained surge in VPN-exploit-driven intrusions across healthcare systems, consistent with the wider organised-criminal pattern.
AI-enabled tradecraft is a structural concern for 2026 healthcare. The Health-ISAC 2026 annual reporting describes the sector as facing an existential cybersecurity crisis with ransomware, supply-chain attacks, and AI-powered threats surging in parallel; the same reporting flags AI-augmented phishing and reconnaissance as the principal threat-tempo multiplier through the rest of the year.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
| THREAT ACTOR PROFILE — Qilin | |
|---|---|
| Aliases | Agenda, Qilin.B |
| Suspected Origin | Russophone |
| Suspected Sponsor | Organised criminal — RaaS |
| Primary Motivation | Financial — ransomware and data extortion |
| Sector Targeting | Healthcare, financial services, professional services, manufacturing |
| Geographic Focus | Global; sustained UK / EU / US / DE activity |
| Signature TTPs | Stolen / brute-forced credentials; exposed RDP / VPN; rapid double extortion; willingness to publish patient data on leak portal |
| Tooling / Malware Families | Qilin / Agenda Rust- and Go-based encryptors; AnyDesk, RustDesk |
| Recent Activity | 103 leak-site postings in April 2026 — leading position globally; behind the most confirmed healthcare-provider attacks during the reporting period |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — INC Ransom | |
|---|---|
| Aliases | INC |
| Suspected Origin | Russophone |
| Suspected Sponsor | Organised criminal — RaaS |
| Primary Motivation | Financial — double-extortion ransomware |
| Sector Targeting | Healthcare, public sector, education |
| Geographic Focus | Global; sustained UK and US presence |
| Signature TTPs | Initial access via exposed remote services; living-off-the-land; double extortion |
| Tooling / Malware Families | INC encryptor; Cobalt Strike; AdFind |
| Recent Activity | Sustained healthcare-and-public-sector leak-site activity through Q1 2026 and into the reporting period |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — SAFEPAY | |
|---|---|
| Aliases | SAFEPAY-RaaS |
| Suspected Origin | Russophone |
| Suspected Sponsor | Organised criminal — RaaS |
| Primary Motivation | Financial — double-extortion ransomware |
| Sector Targeting | Healthcare, manufacturing, professional services |
| Geographic Focus | Global; significant US and EU presence |
| Signature TTPs | Phishing and exposed remote services; double extortion |
| Tooling / Malware Families | SAFEPAY encryptor; living-off-the-land |
| Recent Activity | High-tempo follow-on operator behind a meaningful share of Q1 2026 healthcare ransomware activity |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | MEDIUM |
| THREAT ACTOR PROFILE — NetRunner | |
|---|---|
| Aliases | NetRunner-RaaS |
| Suspected Origin | Mixed |
| Suspected Sponsor | Organised criminal |
| Primary Motivation | Financial — ransomware |
| Sector Targeting | Healthcare, manufacturing |
| Geographic Focus | Global; APAC presence |
| Signature TTPs | Phishing and exposed remote services; double extortion |
| Tooling / Malware Families | NetRunner encryptor |
| Recent Activity | Claimed responsibility for the Nippon Medical School Musashi Kosugi Hospital incident (Feb 2026, 131,700 records) |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | MEDIUM |
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Citrix NetScaler / FortiOS / Exchange exploitation chains continue to drive Qilin / INC / SAFEPAY initial access against healthcare. | H |
| Initial Access | T1078 | Valid Accounts | Stolen / brute-forced VPN credentials remain the dominant initial-access vector across the vertical. | H |
| Initial Access | T1566.001 | Spearphishing Attachment | Healthcare-themed (referral, scheduling, billing) lures continue to be used against UK and US healthcare inboxes; AI-augmented variants flagged by Health-ISAC. | H |
| Persistence | T1543.003 | Create or Modify System Service | Service-creation / scheduled-task-create patterns observed across multiple Qilin and INC intrusions. | M |
| Defence Evasion | T1562.001 | Disable or Modify Tools | PowerShell -ExecutionPolicy Bypass and AV-tampering routines observed across the wider organised-crime landscape. | M |
| Credential Access | T1003 | OS Credential Dumping | LSASS dump and Mimikatz-style activity continues to be a hallmark of post-exploitation in healthcare-provider intrusions. | M |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / Mega.io / putty-pscp exfiltration is the routine pattern across Qilin, INC and SAFEPAY data-theft phases. | H |
| Impact | T1486 | Data Encrypted for Impact | Qilin, INC, SAFEPAY, NetRunner encryptors deploying against healthcare providers at sustained tempo. | H |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Feb 2026 — carry-forward | University of Mississippi Medical Center (US) | Unattributed ransomware | Multi-clinic operational shutdown; computer systems crippled | Public reporting |
| Feb 2026 — carry-forward | Nippon Medical School Musashi Kosugi Hospital (JP) | NetRunner | 131,700 individuals impacted; record-set exfiltration confirmed | Public reporting |
| Q1 2026 | 201 healthcare ransomware attacks (sector aggregate) | Qilin, INC, SAFEPAY, LockBit, The Gentlemen | 120 attacks on direct providers; 81 on sector-adjacent businesses | Comparitech |
| Apr 2026 | Multiple healthcare leak-site listings (global) | Qilin, INC, SAFEPAY | 772 victims claimed across 70 groups in April; healthcare subset includes US and German providers | Ransomware leak-site tracking |
| Through 2025–2026 | H-ISAC Heartbeat — VPN exploit surge | Mixed | Sustained VPN-exploit-driven intrusion volume across healthcare systems | Health-ISAC |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-31431 | Linux Kernel (resource transfer) | 7.8 | Yes | Yes | Apply distro patches; prioritise Internet-facing & multi-tenant hosts |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch immediately; rotate session keys; review for known-exploit IOCs |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-41940 | WebPros cPanel / WP Squared / WHM | 9.8 | No | Suspected | Patch; audit panel admin auth events |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manager | 8.8 | Yes | Yes | Patch immediately; restrict admin plane to mgmt VLAN |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager | 7.5 | Yes | Yes | Rotate SD-WAN passwords; patch |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager | 7.5 | Yes | Yes | Patch; review information disclosure logs |
| CVE-2025-2749 | Kentico Xperience | 9.0 | Yes | Yes | Patch; audit upload paths |
| CVE-2025-32975 | Quest KACE SMA | 8.8 | Yes | Suspected | Patch; restrict KACE management UI |
| CVE-2025-48700 | Synacor Zimbra Collaboration | 6.1 | Yes | Yes | Patch; restrict webmail to authenticated users |
| CVE-2024-27199 | JetBrains TeamCity | 7.3 | Yes | Yes | Patch; rotate CI secrets |
7. Indicators of compromise
Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. IP Insights reputation feed currently lists 812,641 distinct IPv4 addresses across active blocklists (snapshot 04 May 2026 08:15 UTC). AS200651 (FlokiNET) currently lists 110 of 131 known IPs as blacklisted (risk score 100/critical); the AS continues to host bulletproof-style infrastructure observed in the reporting period across phishing, RAT C2, and brute-force activity.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force; IP Insights threat 100/critical, 6 active blacklists; Reliance Jio IN |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd (GB) — IP Insights threat 100/critical, 6 blacklists |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit — IP Insights threat 100/critical, 7 blacklists |
| ASN | AS200651 | 04 May 2026 | H | FlokiNET — 110/131 known IPs blacklisted; bulletproof-style hosting |
| Pattern | rclone / Mega.io egress from corporate file-shares | 27 Apr 2026 | H | Qilin / INC / SAFEPAY data-theft hallmark |
| Pattern | Citrix NetScaler /var/vpn/bookmarks/* directory writes (forthcoming Sigma) | 01 May 2026 | M | CVE-2026-3055 / 4368 expected exploitation indicator class |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment via initial-access broker (Qilin / INC / SAFEPAY) | H | H | CRITICAL |
| Edge-appliance compromise via Citrix NetScaler / FortiOS / Exchange CVEs | H | H | CRITICAL |
| Pure data extortion via shared healthcare SaaS exploitation (Cl0p pattern) | M | H | HIGH |
| Helpdesk / clinical-staff social engineering leading to credential compromise | M | H | HIGH |
| AI-augmented phishing of clinical / billing staff | H | M | HIGH |
| Patient-data extortion / leak-portal publication | H | M | HIGH |
| Supply-chain compromise via shared payer / EHR / pharmacy platform | M | H | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities are: hunting for rclone / Mega.io / putty-pscp egress against EHR / shared-clinical file-stores; PowerShell -ExecutionPolicy Bypass parented by non-baseline processes; LSASS access by non-security-tooling processes; Citrix NetScaler / FortiOS / Exchange exploitation indicators as soon as vendor signatures and Sigma rules are released; and AI-augmented-phishing-flag features in the email-security pipeline. Where customers operate shared payer / EHR / pharmacy platforms, hunting for the Cl0p / MOVEit-pattern web-shell-drop-and-mass-exfil chain is warranted.
Defend
Patching priorities are dominated by Citrix NetScaler ADC / Gateway, FortiOS, Microsoft Exchange and the Linux kernel CVE-2026-31431. The CISA KEV April additions should be patched on the published federal-deadline schedule. Identity-controls hardening to mitigate clinical-staff phishing remains the highest-impact defensive investment; conditional-access rules requiring known-device tokens for high-privilege accounts should be the operating standard. ISO/IEC 27001 Annex A A.5.34 (privacy and protection of PII) and the NHS Data Security and Protection Toolkit are direct levers for UK customers; HIPAA Security Rule for any US-aligned operations. Backup-and-restore drilling against the multi-day operational-outage scenario should be rehearsed at the corporate-IT-and-clinical-systems boundary.
Disrupt
Disruption priorities are sustained sharing of the IP Insights blocklist into customer perimeter-block lists; coordination with Health-ISAC where customers are members; tabletop exercise against the multi-day clinical-systems outage scenario; rehearsal of the patient-data-extortion communications playbook; and coordination with NHS England and NCSC where UK NHS Trust customers are in scope.
10. Forward outlook
It is highly likely that ransomware will remain the principal material-risk scenario for the healthcare vertical over the next reporting cycle, with Qilin, INC Ransom and SAFEPAY the most operationally-relevant operators. (HIGH confidence; 30-day horizon)
It is likely that Citrix NetScaler exploitation will affect at least one healthcare-vertical edge appliance within the next two reporting cycles. (HIGH confidence; 60-day horizon)
It is likely that AI-augmented phishing volumes against clinical staff will rise materially through the next two reporting cycles. (MEDIUM-HIGH confidence; 60-day horizon)
There is a realistic possibility that a UK NHS Trust or material UK healthcare provider will suffer a multi-day operational outage from ransomware within the next six reporting cycles. (MEDIUM confidence; 180-day horizon)
Trigger conditions that would prompt revision of this forecast: a confirmed major ransomware deployment against a UK NHS Trust; in-the-wild exploitation of a previously-quiet healthcare SaaS platform along the Cl0p pattern; a confirmed AI-agent-driven intrusion in the vertical.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC — Threat reports | NCSC.GOV.UK | A1 |
| 2 | CISA KEV — April / May 2026 additions | CISA | A1 |
| 3 | Health-ISAC — 55% surge in cyber incidents in 2025; 2026 escalation | Health-ISAC via Industrial Cyber | A2 |
| 4 | Health-ISAC — Annual Threat Report Health Sector 2026 | Health-ISAC | A2 |
| 5 | Health-ISAC Heartbeat — surge in ransomware and VPN exploits | Health-ISAC via Industrial Cyber | A2 |
| 6 | Comparitech — Healthcare ransomware roundup Q1 2026 | Comparitech | B2 |
| 7 | April 2026 Ransomware Report — 772 victims, 70 groups | BreachSense | B2 |
| 8 | Breached.company — Health-ISAC 2026 Report (existential crisis framing) | Breached.company | C2 |
| 9 | IP Insights — IP / ASN / CIDR threat intelligence API | ipinsights.io | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Healthcare Threat Intelligence Briefing
Healthcare Sector Ransomware Threat Analysis, May 2025
Healthcare threat intelligence report — 4–8 May 2026
The healthcare threat picture for the reporting period continues to escalate.
Healthcare threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the healthcare threat picture remained dominated by ransomware impact on NHS and private-healthcare estates…