Healthcare threat intelligence report — 4–8 May 2026
The healthcare threat picture for the reporting period continues to escalate.
- Reference: TI-2026-0508-005 (public edition)
- Sector: Healthcare
- Reporting period: 4–8 May 2026
- Issued: 8 May 2026 · Lead analyst: Peter Bassill · Analysts: EmilyAI; Peter Bassill
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The healthcare threat picture for the reporting period continues to escalate. Health-ISAC's 2026 Global Health Sector Threat Landscape report describes an industry under sustained ransomware and supply-chain attack pressure, with 455 ransomware incidents tracked globally in 2025 and structural vulnerabilities — particularly in identity controls and supplier ecosystems — driving the upward trajectory into 2026. Q1 2026 figures (Comparitech, carried forward from prior reporting) showed 201 healthcare ransomware attacks (120 against direct providers, 81 against sector-adjacent businesses), and Qilin, INC Ransom and SAFEPAY remain the dominant operators against the vertical.
The single most operationally-significant development inside the reporting window is NCSC's 4 May 2026 blog on the AI-accelerated patch wave. Healthcare's combination of long-life biomedical OT, dispersed clinical-IT estates and acute under-investment in patch-cadence makes the sector disproportionately exposed; the Citrix NetScaler / Ivanti EPMM / PAN-OS User-ID patch wave is therefore particularly consequential.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware will remain the principal material-risk scenario for the healthcare vertical over the next reporting cycle, with Qilin, INC Ransom, SAFEPAY and TheGentlemen the most operationally-relevant operators. Qilin's 103 April leak-site postings and TheGentlemen's rise to second-place ranking confirm sustained operational tempo. (HIGH confidence)
- It is highly likely that VPN- and edge-appliance exploitation will continue to be the dominant initial-access vector against healthcare providers, with the Citrix NetScaler CVEs (3055 / 4368), Ivanti EPMM CVE-2026-6973 and PAN-OS User-ID CVE-2026-0300 the immediate concerns. (HIGH confidence)
- It is likely that AI-enabled ransomware tradecraft — particularly automated phishing and reconnaissance — will materially increase the operational tempo of healthcare-targeted campaigns through the rest of 2026, in line with the H-ISAC and FS-ISAC AI-hardening guidance. (MEDIUM-HIGH confidence)
- It is likely that supply-chain compromise of a healthcare-software vendor will produce at least one nationally-significant healthcare exploitation event within the next two reporting cycles. The ScarCruft gaming-platform supply-chain compromise reported by ESET on 5 May 2026 illustrates the pattern; healthcare's tight concentration of clinical-software vendors makes the sector disproportionately exposed. (MEDIUM confidence)
2. Sector threat landscape
Healthcare remains structurally exposed. The Health-ISAC 2026 Global Health Sector Threat Landscape report describes an industry under sustained ransomware and supply-chain attack pressure, with 455 ransomware incidents tracked globally in 2025 and 4Q2025 showing a significant uplift versus prior quarters. The Q1 2026 Comparitech figures — 201 healthcare ransomware attacks split 120 direct / 81 sector-adjacent — are consistent with the H-ISAC trajectory. Qilin, INC Ransom and SAFEPAY are the dominant operators against the vertical, with Qilin behind the most confirmed provider attacks.
The April 2026 leak-site picture (Breachsense, ransomware.live) — 772 victims claimed across 70 groups — continues to reflect the elevated baseline. Qilin (103 victims, 445 year-to-date) leads for the fourth consecutive month; TheGentlemen (82) has displaced Akira (69); DragonForce (63) holds third. Healthcare-aligned victims continue to be a material subset of monthly leak-site output, and both ransomware.live and the H-ISAC Heartbeat have flagged a sustained surge in VPN-exploitation incidents across healthcare estates throughout early 2026.
Edge-appliance exposure is the dominant gating factor. The Citrix NetScaler ADC / Gateway CVEs (CVE-2026-3055, CVE-2026-4368) carried in from late April; the Ivanti EPMM CVE-2026-6973 (KEV-listed 1 May, FCEB deadline 10 May) and the Palo Alto PAN-OS User-ID portal CVE-2026-0300 (KEV-listed 6 May, FCEB deadline 27 May) collectively define a patch-wave that healthcare's combination of clinical-IT complexity and biomedical-device legacy makes particularly hard to absorb. The MOVEit Automation CVE-2026-4670 active-exploitation reporting matters specifically for any healthcare client running automated EHR or imaging file transfer; the Linux kernel CVE-2026-31431 matters for biomedical-device and clinical-image-processing estates running Linux kernels in the affected range.
Geopolitical pressure shapes the threat picture in healthcare in subtler ways than in defence or financial services. State-aligned hacktivist DDoS continues to be sub-dominant in operational impact compared with criminal ransomware; ScarCruft's gaming-platform supply-chain compromise reported by ESET on 5 May 2026 is illustrative of the third-party-software supply-chain delivery pattern that should be a leading concern for healthcare procurement and vendor-management functions.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
Qilin
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware and data extortion
- Sector Targeting: Healthcare, financial services, professional services, manufacturing
- Geographic Focus: Global
- Signature TTPs: Stolen / brute-forced credential access; abuse of remote-management tooling; double extortion; fast time-to-encrypt
- Tooling / Malware Families: Qilin / Agenda Rust- and Go-based encryptors
- Recent Activity: 103 April 2026 leak-site postings — fourth consecutive month leading; healthcare provider victimology consistent with Q1 2026 figures
- Assessed Threat to Vertical: HIGH — operationally most-relevant single threat
- Analytic Confidence: HIGH
INC Ransom
- Aliases: INC Ransomware
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware and data extortion
- Sector Targeting: Healthcare (acute providers), local government, manufacturing
- Geographic Focus: Global
- Signature TTPs: Stolen-credential and edge-appliance initial access; double-extortion; data-extortion-only mode increasing
- Tooling / Malware Families: INC encryptor; LOLBins
- Recent Activity: Sustained healthcare-provider victimology through Q1 2026
- Assessed Threat to Vertical: HIGH
- Analytic Confidence: MEDIUM-HIGH
SAFEPAY
- Aliases: —
- Suspected Origin: Russophone (assessed)
- Suspected Sponsor: Organised criminal
- Primary Motivation: Financial — ransomware
- Sector Targeting: Healthcare, professional services, manufacturing
- Geographic Focus: Global; North American and EU activity
- Signature TTPs: Stolen-credential and edge-appliance initial access; double-extortion
- Tooling / Malware Families: SAFEPAY encryptor
- Recent Activity: Healthcare-aligned victimology consistent with Q1 2026 trend
- Assessed Threat to Vertical: MEDIUM-HIGH
- Analytic Confidence: MEDIUM
TheGentlemen
- Aliases: —
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware
- Sector Targeting: Healthcare-adjacent, manufacturing, professional services
- Geographic Focus: Global; growing UK and EU activity
- Signature TTPs: Edge-appliance and stolen-credential initial access; double-extortion
- Tooling / Malware Families: Custom encryptor
- Recent Activity: 82 April 2026 leak-site postings — second-place global ranking
- Assessed Threat to Vertical: MEDIUM-HIGH — rising tempo
- Analytic Confidence: MEDIUM
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1133 | External Remote Services | Citrix NetScaler / Ivanti EPMM / PAN-OS additions to KEV expose healthcare edge appliances; VPN exploitation flagged as the dominant access vector by H-ISAC. | H |
| Initial Access | T1190 | Exploit Public-Facing Application | MOVEit Automation CVE-2026-4670 and Weaver E-Cology CVE-2026-22679 add unauthenticated RCE surfaces to healthcare trust platforms. | H |
| Initial Access | T1199 | Trusted Relationship | Vendor-supply-chain compromise of clinical-software providers — reinforced by ScarCruft (5 May 2026) supply-chain pattern. | M |
| Initial Access | T1566.001 | Spearphishing Attachment | Sustained AI-assisted phishing tradecraft against clinical-administration inboxes. | M |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Linux kernel CVE-2026-31431 active exploitation has direct relevance to biomedical-device and clinical-image-processing Linux estates. | H |
| Impact | T1486 | Data Encrypted for Impact | Qilin, INC Ransom, SAFEPAY, TheGentlemen affiliates continue to deploy encryptors against healthcare at scale. | H |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| May 2026 | Multiple healthcare leak-site listings (global) | Qilin, INC Ransom, SAFEPAY, TheGentlemen | Healthcare subset of the 772 April leak-site victims; consistent with H-ISAC sustained-surge characterisation | Ransomware.live; Breachsense |
| May 2026 | Vulnerability patch wave (sector-wide) | Multiple | NCSC 4 May 2026 blog warns AI-accelerated vulnerability discovery; Linux-kernel CVE-2026-31431 of acute relevance to biomedical-device estates | NCSC; CISA |
| Q1 2026 | 201 healthcare ransomware attacks (carry-forward) | Multiple | 120 direct providers, 81 sector-adjacent businesses | Comparitech |
| Recent | ScarCruft gaming-platform supply-chain compromise | ScarCruft (DPRK-aligned) | Illustrative of third-party-software supply-chain delivery pattern relevant to healthcare procurement | ESET (5 May 2026) |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 8.8 | Yes (1 May) | Yes | Patch immediately; FCEB deadline 10 May; rotate admin sessions; review clinical-mobile estate |
| CVE-2026-0300 | Palo Alto Networks PAN-OS User-ID Portal | 9.8 | Yes (6 May) | Yes | Patch immediately; FCEB deadline 27 May; restrict portal exposure |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch immediately; rotate session keys; clinical remote-access of acute relevance |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-31431 | Linux Kernel (resource transfer) | 7.8 | Yes | Yes | Apply distro patches; biomedical-device and image-processing Linux hosts of acute relevance |
| CVE-2026-4670 | Progress MOVEit Automation | 9.8 | Pending | Yes | Patch; audit EHR and imaging MFT operator authentication |
| CVE-2026-22679 | Weaver E-Cology | 9.8 | — | Yes | Patch; restrict OA platform to internal networks |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. The IP Insights enrichment service (https://ipinsights.io) provides the underlying threat-score and blocklist coverage.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 87[.]103[.]126[.]54 | 30 Apr 2026 | H | SSH brute-force — Vodafone PT (AS12353); IP Insights threat 100/critical, 6 active blacklists |
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force — Reliance Jio IN (AS55836); IP Insights threat 100/critical, 6 active blacklists |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd / INTERNET-MEASUREMENT (AS211298); cross-tenant scanning |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit (for-privacy.net); 7 active blacklists |
| ASN | AS200651 | Ongoing | H | FlokiNET — 110/132 known IPs blacklisted; bulletproof-style hosting |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| Ransomware deployment via VPN / edge-appliance exploitation against acute-provider estate | H | H | CRITICAL |
| Vendor-supply-chain compromise of clinical-software provider | M | H | HIGH |
| Pure data extortion via EHR / imaging MFT platform compromise (MOVEit pattern) | M | H | HIGH |
| Linux kernel exploitation against biomedical-device estate (CVE-2026-31431) | M | H | HIGH |
| AI-assisted phishing of clinical-administration inboxes leading to credential theft | H | M | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities for the next reporting cycle should focus on three concurrent themes. First, edge-appliance exploitation telemetry — Citrix NetScaler, Ivanti EPMM and PAN-OS User-ID portal access correlated against published indicator-of-compromise sets, with explicit alerting on first-seen IP geolocation for clinical remote-access identities. The H-ISAC Heartbeat and Health Sector Coordinating Council remain the highest-value sector intelligence sources.
Defend
Patch posture and identity controls are the highest-leverage defensive priorities. The Ivanti EPMM, PAN-OS, NetScaler, MOVEit Automation and Linux kernel patch-wave should be circulated to all healthcare clients with edge-appliance, mobile-device-management, or biomedical-device exposure. MFA on every clinical remote-access identity, with phishing-resistant assurance for privileged accounts, is non-negotiable. Vendor-management controls — particularly third-party software-supply-chain attestation — are the highest-leverage second priority, in light of the ScarCruft pattern. ISO/IEC 27001 Annex A 5.18, 8.5 and 8.7 are the relevant references; in the UK, the Data Security and Protection Toolkit (DSPT) and the NHS Digital Cyber Associate Network's published guidance remain authoritative.
Disrupt
Disruption priorities are concentrated in three areas. First, indicator sharing within Health-ISAC and CiSP, particularly the IP Insights enrichment data for the Vodafone PT and Reliance Jio source-IP patterns. Second, takedown coordination on phishing infrastructure attributable to AS200651 (FlokiNET), including any healthcare-themed pretext kits (NHS, Patient Access, GP-systems impersonation). Third, tabletop exercise activity covering the EHR-platform-extortion scenario at acute-provider scope.
10. Forward outlook
It is highly likely that ransomware against the healthcare vertical will continue at sustained tempo through Q2 and Q3 2026, with Qilin, INC Ransom and SAFEPAY the most operationally-relevant operators and biomedical-device exposure (Linux kernel CVE-2026-31431) the leading emerging concern. It is likely that at least one nationally-significant supply-chain event in healthcare clinical-software will materialise within the next two reporting cycles.
Trigger conditions warranting forecast revision: confirmed exploitation of CVE-2026-6973 against a UK healthcare provider; confirmed exploitation of CVE-2026-31431 against a biomedical-device estate; or material change in the H-ISAC Heartbeat-reported VPN-exploitation tempo. Intelligence gaps to close: independent corroboration of the ScarCruft-pattern supply-chain risk to UK clinical-software vendors.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC – Preparing for a vulnerability patch wave (4 May 2026 blog) | NCSC | A2 |
| 2 | NCSC Annual Review 2025 – ransomware and nationally significant incidents | NCSC | A1 |
| 3 | UK Cyber Security Breaches Survey 2025/2026 (DSIT) | GOV.UK | A1 |
| 4 | CISA Known Exploited Vulnerabilities Catalogue (rolling) | CISA | A1 |
| 5 | CISA Alert – Ivanti EPMM CVE-2026-6973 added to KEV (1 May 2026) | CISA | A1 |
| 6 | CISA Alert – Palo Alto PAN-OS CVE-2026-0300 added to KEV (6 May 2026) | CISA | A1 |
| 7 | Breachsense – April 2026 Ransomware Report (772 victims, 70 groups) | Breachsense | B2 |
| 8 | Ransomware.live – sector and group leak-site index | Ransomware.live | B2 |
| 9 | IP Insights – IP reputation and blocklist enrichment service | UK Cyber Defence | A1 |
| 11 | Health-ISAC – 2026 Global Health Sector Threat Landscape Report | Health-ISAC | A1 |
| 12 | Industrial Cyber – Health-ISAC reports 55% surge in cyber incidents in 2025 | Industrial Cyber | B2 |
| 13 | Industrial Cyber – Health-ISAC Heartbeat flags surge in ransomware, VPN exploits | Industrial Cyber | B2 |
| 14 | The Hacker News – CISA Adds Linux Kernel CVE-2026-31431 to KEV | The Hacker News | B2 |
| 15 | ESET – ScarCruft gaming-platform supply-chain compromise (5 May 2026) | ESET | A2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Healthcare Threat Intelligence Briefing
Healthcare Sector Ransomware Threat Analysis, May 2025
Healthcare threat intelligence report — 27 April – 3 May 2026
The healthcare threat picture for the reporting period continues to escalate. Health-ISAC reporting flags a 55% surge in cyber incidents in 2025 with continued escalation expected in 2026.
Healthcare threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the healthcare threat picture remained dominated by ransomware impact on NHS and private-healthcare estates…