SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Healthcare threat intelligence report — 4–8 May 2026

The healthcare threat picture for the reporting period continues to escalate.

  • Reference: TI-2026-0508-005 (public edition)
  • Sector: Healthcare
  • Reporting period: 4–8 May 2026
  • Issued: 8 May 2026 · Lead analyst: Peter Bassill · Analysts: EmilyAI; Peter Bassill

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

The healthcare threat picture for the reporting period continues to escalate. Health-ISAC's 2026 Global Health Sector Threat Landscape report describes an industry under sustained ransomware and supply-chain attack pressure, with 455 ransomware incidents tracked globally in 2025 and structural vulnerabilities — particularly in identity controls and supplier ecosystems — driving the upward trajectory into 2026. Q1 2026 figures (Comparitech, carried forward from prior reporting) showed 201 healthcare ransomware attacks (120 against direct providers, 81 against sector-adjacent businesses), and Qilin, INC Ransom and SAFEPAY remain the dominant operators against the vertical.

The single most operationally-significant development inside the reporting window is NCSC's 4 May 2026 blog on the AI-accelerated patch wave. Healthcare's combination of long-life biomedical OT, dispersed clinical-IT estates and acute under-investment in patch-cadence makes the sector disproportionately exposed; the Citrix NetScaler / Ivanti EPMM / PAN-OS User-ID patch wave is therefore particularly consequential.

Key Judgements

The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that ransomware will remain the principal material-risk scenario for the healthcare vertical over the next reporting cycle, with Qilin, INC Ransom, SAFEPAY and TheGentlemen the most operationally-relevant operators. Qilin's 103 April leak-site postings and TheGentlemen's rise to second-place ranking confirm sustained operational tempo. (HIGH confidence)
  2. It is highly likely that VPN- and edge-appliance exploitation will continue to be the dominant initial-access vector against healthcare providers, with the Citrix NetScaler CVEs (3055 / 4368), Ivanti EPMM CVE-2026-6973 and PAN-OS User-ID CVE-2026-0300 the immediate concerns. (HIGH confidence)
  3. It is likely that AI-enabled ransomware tradecraft — particularly automated phishing and reconnaissance — will materially increase the operational tempo of healthcare-targeted campaigns through the rest of 2026, in line with the H-ISAC and FS-ISAC AI-hardening guidance. (MEDIUM-HIGH confidence)
  4. It is likely that supply-chain compromise of a healthcare-software vendor will produce at least one nationally-significant healthcare exploitation event within the next two reporting cycles. The ScarCruft gaming-platform supply-chain compromise reported by ESET on 5 May 2026 illustrates the pattern; healthcare's tight concentration of clinical-software vendors makes the sector disproportionately exposed. (MEDIUM confidence)

2. Sector threat landscape

Healthcare remains structurally exposed. The Health-ISAC 2026 Global Health Sector Threat Landscape report describes an industry under sustained ransomware and supply-chain attack pressure, with 455 ransomware incidents tracked globally in 2025 and 4Q2025 showing a significant uplift versus prior quarters. The Q1 2026 Comparitech figures — 201 healthcare ransomware attacks split 120 direct / 81 sector-adjacent — are consistent with the H-ISAC trajectory. Qilin, INC Ransom and SAFEPAY are the dominant operators against the vertical, with Qilin behind the most confirmed provider attacks.

The April 2026 leak-site picture (Breachsense, ransomware.live) — 772 victims claimed across 70 groups — continues to reflect the elevated baseline. Qilin (103 victims, 445 year-to-date) leads for the fourth consecutive month; TheGentlemen (82) has displaced Akira (69); DragonForce (63) holds third. Healthcare-aligned victims continue to be a material subset of monthly leak-site output, and both ransomware.live and the H-ISAC Heartbeat have flagged a sustained surge in VPN-exploitation incidents across healthcare estates throughout early 2026.

Edge-appliance exposure is the dominant gating factor. The Citrix NetScaler ADC / Gateway CVEs (CVE-2026-3055, CVE-2026-4368) carried in from late April; the Ivanti EPMM CVE-2026-6973 (KEV-listed 1 May, FCEB deadline 10 May) and the Palo Alto PAN-OS User-ID portal CVE-2026-0300 (KEV-listed 6 May, FCEB deadline 27 May) collectively define a patch-wave that healthcare's combination of clinical-IT complexity and biomedical-device legacy makes particularly hard to absorb. The MOVEit Automation CVE-2026-4670 active-exploitation reporting matters specifically for any healthcare client running automated EHR or imaging file transfer; the Linux kernel CVE-2026-31431 matters for biomedical-device and clinical-image-processing estates running Linux kernels in the affected range.

Geopolitical pressure shapes the threat picture in healthcare in subtler ways than in defence or financial services. State-aligned hacktivist DDoS continues to be sub-dominant in operational impact compared with criminal ransomware; ScarCruft's gaming-platform supply-chain compromise reported by ESET on 5 May 2026 is illustrative of the third-party-software supply-chain delivery pattern that should be a leading concern for healthcare procurement and vendor-management functions.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.

Qilin

  • Aliases: Agenda, Qilin.B
  • Suspected Origin: Russophone
  • Suspected Sponsor: Organised criminal — RaaS
  • Primary Motivation: Financial — ransomware and data extortion
  • Sector Targeting: Healthcare, financial services, professional services, manufacturing
  • Geographic Focus: Global
  • Signature TTPs: Stolen / brute-forced credential access; abuse of remote-management tooling; double extortion; fast time-to-encrypt
  • Tooling / Malware Families: Qilin / Agenda Rust- and Go-based encryptors
  • Recent Activity: 103 April 2026 leak-site postings — fourth consecutive month leading; healthcare provider victimology consistent with Q1 2026 figures
  • Assessed Threat to Vertical: HIGH — operationally most-relevant single threat
  • Analytic Confidence: HIGH

INC Ransom

  • Aliases: INC Ransomware
  • Suspected Origin: Russophone
  • Suspected Sponsor: Organised criminal — RaaS
  • Primary Motivation: Financial — ransomware and data extortion
  • Sector Targeting: Healthcare (acute providers), local government, manufacturing
  • Geographic Focus: Global
  • Signature TTPs: Stolen-credential and edge-appliance initial access; double-extortion; data-extortion-only mode increasing
  • Tooling / Malware Families: INC encryptor; LOLBins
  • Recent Activity: Sustained healthcare-provider victimology through Q1 2026
  • Assessed Threat to Vertical: HIGH
  • Analytic Confidence: MEDIUM-HIGH

SAFEPAY

  • Aliases:
  • Suspected Origin: Russophone (assessed)
  • Suspected Sponsor: Organised criminal
  • Primary Motivation: Financial — ransomware
  • Sector Targeting: Healthcare, professional services, manufacturing
  • Geographic Focus: Global; North American and EU activity
  • Signature TTPs: Stolen-credential and edge-appliance initial access; double-extortion
  • Tooling / Malware Families: SAFEPAY encryptor
  • Recent Activity: Healthcare-aligned victimology consistent with Q1 2026 trend
  • Assessed Threat to Vertical: MEDIUM-HIGH
  • Analytic Confidence: MEDIUM

TheGentlemen

  • Aliases:
  • Suspected Origin: Russophone
  • Suspected Sponsor: Organised criminal — RaaS
  • Primary Motivation: Financial — ransomware
  • Sector Targeting: Healthcare-adjacent, manufacturing, professional services
  • Geographic Focus: Global; growing UK and EU activity
  • Signature TTPs: Edge-appliance and stolen-credential initial access; double-extortion
  • Tooling / Malware Families: Custom encryptor
  • Recent Activity: 82 April 2026 leak-site postings — second-place global ranking
  • Assessed Threat to Vertical: MEDIUM-HIGH — rising tempo
  • Analytic Confidence: MEDIUM

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConf.
Initial AccessT1133External Remote ServicesCitrix NetScaler / Ivanti EPMM / PAN-OS additions to KEV expose healthcare edge appliances; VPN exploitation flagged as the dominant access vector by H-ISAC.H
Initial AccessT1190Exploit Public-Facing ApplicationMOVEit Automation CVE-2026-4670 and Weaver E-Cology CVE-2026-22679 add unauthenticated RCE surfaces to healthcare trust platforms.H
Initial AccessT1199Trusted RelationshipVendor-supply-chain compromise of clinical-software providers — reinforced by ScarCruft (5 May 2026) supply-chain pattern.M
Initial AccessT1566.001Spearphishing AttachmentSustained AI-assisted phishing tradecraft against clinical-administration inboxes.M
Privilege EscalationT1068Exploitation for Privilege EscalationLinux kernel CVE-2026-31431 active exploitation has direct relevance to biomedical-device and clinical-image-processing Linux estates.H
ImpactT1486Data Encrypted for ImpactQilin, INC Ransom, SAFEPAY, TheGentlemen affiliates continue to deploy encryptors against healthcare at scale.H

5. Notable incidents and campaigns

DateAffected Org / Sub-SectorSuspected AttributionImpact SummaryReference
May 2026Multiple healthcare leak-site listings (global)Qilin, INC Ransom, SAFEPAY, TheGentlemenHealthcare subset of the 772 April leak-site victims; consistent with H-ISAC sustained-surge characterisationRansomware.live; Breachsense
May 2026Vulnerability patch wave (sector-wide)MultipleNCSC 4 May 2026 blog warns AI-accelerated vulnerability discovery; Linux-kernel CVE-2026-31431 of acute relevance to biomedical-device estatesNCSC; CISA
Q1 2026201 healthcare ransomware attacks (carry-forward)Multiple120 direct providers, 81 sector-adjacent businessesComparitech
RecentScarCruft gaming-platform supply-chain compromiseScarCruft (DPRK-aligned)Illustrative of third-party-software supply-chain delivery pattern relevant to healthcare procurementESET (5 May 2026)

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSSKEVActive ExploitationRecommended Action
CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM)8.8Yes (1 May)YesPatch immediately; FCEB deadline 10 May; rotate admin sessions; review clinical-mobile estate
CVE-2026-0300Palo Alto Networks PAN-OS User-ID Portal9.8Yes (6 May)YesPatch immediately; FCEB deadline 27 May; restrict portal exposure
CVE-2026-3055Citrix NetScaler ADC / Gateway9.3YesYesPatch immediately; rotate session keys; clinical remote-access of acute relevance
CVE-2026-4368Citrix NetScaler ADC / Gateway8.8YesYesPatch; audit Gateway session logs
CVE-2026-31431Linux Kernel (resource transfer)7.8YesYesApply distro patches; biomedical-device and image-processing Linux hosts of acute relevance
CVE-2026-4670Progress MOVEit Automation9.8PendingYesPatch; audit EHR and imaging MFT operator authentication
CVE-2026-22679Weaver E-Cology9.8YesPatch; restrict OA platform to internal networks

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. The IP Insights enrichment service (https://ipinsights.io) provides the underlying threat-score and blocklist coverage.

TypeIndicatorFirst SeenConf.Notes
IPv487[.]103[.]126[.]5430 Apr 2026HSSH brute-force — Vodafone PT (AS12353); IP Insights threat 100/critical, 6 active blacklists
IPv4136[.]232[.]11[.]1020 Apr 2026HSSH brute-force — Reliance Jio IN (AS55836); IP Insights threat 100/critical, 6 active blacklists
IPv487[.]236[.]176[.]4502 May 2026MConstantine Cybersecurity Ltd / INTERNET-MEASUREMENT (AS211298); cross-tenant scanning
IPv4185[.]220[.]101[.]3003 May 2026MTor exit (for-privacy.net); 7 active blacklists
ASNAS200651OngoingHFlokiNET — 110/132 known IPs blacklisted; bulletproof-style hosting

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite
Ransomware deployment via VPN / edge-appliance exploitation against acute-provider estateHHCRITICAL
Vendor-supply-chain compromise of clinical-software providerMHHIGH
Pure data extortion via EHR / imaging MFT platform compromise (MOVEit pattern)MHHIGH
Linux kernel exploitation against biomedical-device estate (CVE-2026-31431)MHHIGH
AI-assisted phishing of clinical-administration inboxes leading to credential theftHMHIGH

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection priorities for the next reporting cycle should focus on three concurrent themes. First, edge-appliance exploitation telemetry — Citrix NetScaler, Ivanti EPMM and PAN-OS User-ID portal access correlated against published indicator-of-compromise sets, with explicit alerting on first-seen IP geolocation for clinical remote-access identities. The H-ISAC Heartbeat and Health Sector Coordinating Council remain the highest-value sector intelligence sources.

Defend

Patch posture and identity controls are the highest-leverage defensive priorities. The Ivanti EPMM, PAN-OS, NetScaler, MOVEit Automation and Linux kernel patch-wave should be circulated to all healthcare clients with edge-appliance, mobile-device-management, or biomedical-device exposure. MFA on every clinical remote-access identity, with phishing-resistant assurance for privileged accounts, is non-negotiable. Vendor-management controls — particularly third-party software-supply-chain attestation — are the highest-leverage second priority, in light of the ScarCruft pattern. ISO/IEC 27001 Annex A 5.18, 8.5 and 8.7 are the relevant references; in the UK, the Data Security and Protection Toolkit (DSPT) and the NHS Digital Cyber Associate Network's published guidance remain authoritative.

Disrupt

Disruption priorities are concentrated in three areas. First, indicator sharing within Health-ISAC and CiSP, particularly the IP Insights enrichment data for the Vodafone PT and Reliance Jio source-IP patterns. Second, takedown coordination on phishing infrastructure attributable to AS200651 (FlokiNET), including any healthcare-themed pretext kits (NHS, Patient Access, GP-systems impersonation). Third, tabletop exercise activity covering the EHR-platform-extortion scenario at acute-provider scope.

10. Forward outlook

It is highly likely that ransomware against the healthcare vertical will continue at sustained tempo through Q2 and Q3 2026, with Qilin, INC Ransom and SAFEPAY the most operationally-relevant operators and biomedical-device exposure (Linux kernel CVE-2026-31431) the leading emerging concern. It is likely that at least one nationally-significant supply-chain event in healthcare clinical-software will materialise within the next two reporting cycles.

Trigger conditions warranting forecast revision: confirmed exploitation of CVE-2026-6973 against a UK healthcare provider; confirmed exploitation of CVE-2026-31431 against a biomedical-device estate; or material change in the H-ISAC Heartbeat-reported VPN-exploitation tempo. Intelligence gaps to close: independent corroboration of the ScarCruft-pattern supply-chain risk to UK clinical-software vendors.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC – Preparing for a vulnerability patch wave (4 May 2026 blog)NCSCA2
2NCSC Annual Review 2025 – ransomware and nationally significant incidentsNCSCA1
3UK Cyber Security Breaches Survey 2025/2026 (DSIT)GOV.UKA1
4CISA Known Exploited Vulnerabilities Catalogue (rolling)CISAA1
5CISA Alert – Ivanti EPMM CVE-2026-6973 added to KEV (1 May 2026)CISAA1
6CISA Alert – Palo Alto PAN-OS CVE-2026-0300 added to KEV (6 May 2026)CISAA1
7Breachsense – April 2026 Ransomware Report (772 victims, 70 groups)BreachsenseB2
8Ransomware.live – sector and group leak-site indexRansomware.liveB2
9IP Insights – IP reputation and blocklist enrichment serviceUK Cyber DefenceA1
11Health-ISAC – 2026 Global Health Sector Threat Landscape ReportHealth-ISACA1
12Industrial Cyber – Health-ISAC reports 55% surge in cyber incidents in 2025Industrial CyberB2
13Industrial Cyber – Health-ISAC Heartbeat flags surge in ransomware, VPN exploitsIndustrial CyberB2
14The Hacker News – CISA Adds Linux Kernel CVE-2026-31431 to KEVThe Hacker NewsB2
15ESET – ScarCruft gaming-platform supply-chain compromise (5 May 2026)ESETA2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.