Healthcare threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the healthcare threat picture remained dominated by ransomware impact on NHS and private-healthcare estates…
- Reference: TI-2026-0517-005 (public edition)
- Sector: Healthcare
- Reporting period: 11–17 May 2026
- Issued: 17 May 2026 · Lead analyst: Peter Bassill · Analysts: EmilyAI; Peter Bassill
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
During the reporting period 11 May 2026 – 17 May 2026 the healthcare threat picture remained dominated by ransomware impact on NHS and private-healthcare estates, with the long-tail of the June 2024 Synnovis / Qilin attack continuing to disrupt London NHS Trust pathology services nearly two years on. The Health-ISAC Heartbeat report carried into the period flags a sustained surge in ransomware and VPN-exploit activity across healthcare systems. The 14 May 2026 addition of CVE-2026-20182 (Cisco Catalyst SD-WAN Controller authentication bypass) to the CISA KEV catalogue under Emergency Directive 26-03 is materially relevant to multi-site Trusts and ICBs operating Cisco SD-WAN connectivity. Ivanti EPMM CVE-2026-6973 active exploitation (FCEB deadline 10 May passed) remains a primary risk for healthcare MDM estates.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware against UK healthcare — Qilin pre-eminently, plus INC Ransom, Akira and DragonForce affiliates — will continue to drive the majority of material risk to the vertical over the next reporting cycle. Q1 2026 leak-site volume (2,122 victims, 91 active DLS, Check Point Research) confirms continued tempo (HIGH confidence).
- It is likely that the Synnovis / Qilin disclosure tail will continue to drive supply-chain due-diligence scrutiny across NHS Trusts and pathology providers, with at least one further enforcement-related disclosure plausible within the next two reporting cycles (MEDIUM-HIGH confidence).
- It is likely that CISA Emergency Directive 26-03 (Cisco SD-WAN, CVE-2026-20182) will produce at least one publicly-disclosed UK healthcare exploitation event within the next two reporting cycles. Multi-site Trusts and ICBs frequently rely on Cisco SD-WAN for inter-site connectivity (MEDIUM-HIGH confidence).
- It is highly likely that Ivanti EPMM CVE-2026-6973 exposure across NHS managed-mobile fleets will require rapid patching and post-patch hunting; the FCEB deadline has passed and active exploitation continues globally (HIGH confidence).
- There is a realistic possibility of an opportunistic ransomware operator targeting a UK private-healthcare or imaging-services provider during the next reporting cycle — these have been less-publicly-defended than NHS Trusts post-Synnovis (MEDIUM confidence).
2. Sector threat landscape
The UK healthcare sector continues to absorb the operational and clinical-impact consequences of the June 2024 Synnovis ransomware attack attributed to Qilin. The breach has been officially linked to at least one patient death and more than 120 cases of patient harm, with 4,913 acute outpatient appointments and 1,391 operations disrupted. As of early 2026, pathology systems at South London and Maudsley NHS Foundation Trust have not been fully restored, with the trust still operating in business-continuity mode relying on paper processes and manual uploads. This continues to function as the structural reference case for the vertical and as the operational benchmark against which Trust and ICB cyber-resilience planning is being measured.
The Health-ISAC Heartbeat report carried into the period flags a sustained surge in ransomware and VPN-exploit activity across healthcare systems. The 14 May 2026 addition of CVE-2026-20182 (Cisco Catalyst SD-WAN Controller authentication bypass) to the CISA KEV catalogue under Emergency Directive 26-03 is directly relevant to multi-site Trusts and ICBs operating Cisco SD-WAN connectivity, and to private-healthcare and imaging-services providers operating multi-site WANs. Ivanti EPMM CVE-2026-6973 (active exploitation, FCEB deadline 10 May passed) is a primary risk for healthcare MDM estates. Citrix NetScaler ADC / Gateway CVEs (CVE-2026-3055 / CVE-2026-4368) remain on the same active-exploitation footing — many NHS clinician remote-access services are routed through NetScaler.
Geopolitical pressure shapes the threat picture in healthcare in subtler ways than in defence or financial services. State-aligned hacktivist DDoS continues to be sub-dominant in operational impact compared with criminal ransomware; ScarCruft's gaming-platform supply-chain compromise reported by ESET on 5 May 2026 is illustrative of the third-party-software supply-chain delivery pattern that should be a leading concern for healthcare procurement and vendor-management functions.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
Threat Actor Profile — Qilin
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS (kremlin-tolerated)
- Primary Motivation: Financial — ransomware and data extortion
- Sector Targeting: Healthcare, financial services, professional services, manufacturing
- Geographic Focus: Global; sustained UK NHS / private-healthcare victimology
- Signature TTPs: Initial access via stolen / brute-forced credentials, edge-appliance exploitation, third-party / supplier compromise; double-extortion
- Tooling / Malware Families: Qilin / Agenda Rust- and Go-based encryptor variants; AnyDesk, RustDesk, ScreenConnect
- Recent Activity: 338 Q1 2026 leak-site postings (Check Point Research); Synnovis attribution carried forward — patient-harm impact, business-continuity disruption to NHS pathology services into 2026
- Assessed Threat to Vertical: HIGH — proven UK NHS victimology, patient-harm impact, sustained operational tempo
- Analytic Confidence: HIGH
Threat Actor Profile — INC Ransom
- Aliases: INC
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware and data extortion
- Sector Targeting: Healthcare, legal services, professional services
- Geographic Focus: Global
- Signature TTPs: Initial access via stolen credentials, edge-appliance exploitation; data-exfiltration prioritised; double-extortion
- Tooling / Malware Families: INC encryptor; data-staging via Rclone / MEGA
- Recent Activity: Sustained healthcare and legal-sector tempo through 2025-2026
- Assessed Threat to Vertical: HIGH — vertical-aligned victimology
- Analytic Confidence: HIGH
Threat Actor Profile — Akira
- Aliases: Akira ransomware
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware and data extortion
- Sector Targeting: Healthcare, professional services, manufacturing
- Geographic Focus: Global
- Signature TTPs: Initial access via stolen credentials and edge-appliance exploitation; rapid lateral movement; double-extortion
- Tooling / Malware Families: Akira encryptor; LOLBins
- Recent Activity: $244m total proceeds and 34 percent share of IR engagements; sector selection optimised for ransom-pressure response
- Assessed Threat to Vertical: HIGH — applicable to under-defended healthcare estates
- Analytic Confidence: HIGH
Threat Actor Profile — DragonForce affiliate cluster
- Aliases: Various Scattered-Spider-aligned affiliates
- Suspected Origin: Mixed
- Suspected Sponsor: Organised criminal — affiliate of multiple RaaS
- Primary Motivation: Financial — ransomware, data extortion
- Sector Targeting: Retail, healthcare, professional services
- Geographic Focus: Global; high-tempo UK and North American operations
- Signature TTPs: Helpdesk social engineering; MFA fatigue; identity-provider abuse
- Tooling / Malware Families: DragonForce ransomware payload
- Recent Activity: M&S / Co-op campaign provides the replicable playbook; applicable to private-healthcare estates with outsourced-IT helpdesk
- Assessed Threat to Vertical: MEDIUM — applicable to outsourced-IT healthcare estates
- Analytic Confidence: MEDIUM
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Cisco Catalyst SD-WAN CVE-2026-20182 (KEV 14 May, ED 26-03) and Ivanti EPMM CVE-2026-6973 (active exploitation, FCEB deadline passed) place authentication-bypass and pre-auth RCE on healthcare edge surfaces. | H |
| Initial Access | T1133 | External Remote Services | Citrix NetScaler ADC / Gateway, Palo Alto PAN-OS User-ID Portal expose NHS clinician and Trust remote-access surfaces. | H |
| Initial Access | T1199 | Trusted Relationship | Supplier-compromise pattern — Synnovis (pathology) is the structural reference case; pathology, imaging and managed-IT supplier compromise propagates rapidly into Trust estates. | H |
| Lateral Movement | T1021.002 | Remote Services: SMB/Windows Admin Shares | Continued use across clinical-corporate VLAN trust relationships where segmentation is incomplete. | M |
| Collection | T1530 | Data from Cloud Storage Object | Anomalous bulk-export from EPR, PACS and LIS platforms — INC Ransom / Qilin precursor. | M |
| Impact | T1486 | Data Encrypted for Impact | Qilin, INC Ransom, Akira affiliates deploying encryptors against healthcare estates; Synnovis pattern is the structural reference case. | H |
| Impact | T1657 | Financial Theft | BEC and invoice-fraud tradecraft against Trust finance and procurement teams. | M |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Ongoing | Synnovis / Qilin attack disclosure tail (NHS London Trusts) | Qilin | Patient-harm impact (at least one death, 120+ harm cases); SLaM still in business-continuity mode in 2026; reference case for sector tabletop exercises | NHS public reporting; The Record |
| Ongoing | Health-ISAC Heartbeat — sustained ransomware and VPN-exploit surge | Multiple | Sector-wide warning across NHS, private-healthcare and supplier estates | Health-ISAC / Industrial Cyber |
| 14 May 2026 | Cisco Catalyst SD-WAN exploitation surface (sector-wide) | Multiple — CISA ED 26-03 | CVE-2026-20182 authentication-bypass added to KEV; ED 26-03 hunt-and-hardening direction; multi-site Trusts and private-healthcare providers with Cisco SD-WAN immediately exposed | CISA; NCSC |
| May 2026 | Healthcare leak-site listings (global) | Qilin, INC Ransom, Akira | Healthcare subset of Q1 2026 leak-site total (2,122 victims, 91 active DLS, Check Point Research) | Check Point Research; Ransomware.live |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller (authentication bypass) | 9.8 | Yes (14 May) | Yes | Patch immediately; align with CISA ED 26-03 / Supplemental Direction; hunt for compromise; FCEB hardening guidance applies |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 8.8 | Yes (1 May) | Yes | Patch immediately; FCEB deadline now passed (10 May); rotate admin sessions; review MDM admin auth logs |
| CVE-2026-0300 | Palo Alto Networks PAN-OS User-ID Portal | 9.8 | Yes (6 May) | Yes | Patch immediately; FCEB deadline 27 May; restrict portal exposure |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch; rotate session keys; hunt for indicators |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-4670 | Progress MOVEit Automation (< 2025.1.5 / 2025.0.9 / 2024.1.8) | 9.8 | Yes | Yes (low-complexity) | Patch; audit MFT operator and admin authentication |
| CVE-2026-8043 | Ivanti Xtraction (external control of file name, RCE) | 9.6 | — | Pending | Patch; restrict reporting console exposure |
| CVE-2026-44277 | Fortinet FortiAuthenticator (improper access control) | 9.1 | — | Pending | Patch; restrict management plane exposure |
| CVE-2026-26083 | Fortinet FortiSandbox (missing authorisation, RCE) | 9.1 | — | Pending | Patch; restrict sandbox API exposure |
| CVE-2026-34260 | SAP S/4HANA Enterprise Search for ABAP | 9.6 | — | Pending | Patch; restrict access to enterprise search endpoints |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. The IP Insights enrichment service (https://ipinsights.io) provides the underlying threat-score and blocklist coverage.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force pattern — Reliance Jio IN (AS55836); IP Insights threat 100/critical, 7 active blacklists; carry-forward IOC |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd / INTERNET-MEASUREMENT (AS211298) — IP Insights threat 100/critical; mass scanning |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit (for-privacy.net) — IP Insights threat 100/critical |
| ASN | AS200651 | Ongoing | H | FlokiNET — 112/134 known IPs blacklisted; risk 100/critical; risk breakdown low 19 / med 3 / high 31 / critical 81; bulletproof hosting |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| Pathology / imaging / LIS supplier ransomware compromise leading to clinical-service disruption (Synnovis pattern) | M | H | CRITICAL |
| Cisco SD-WAN exploitation chain (CVE-2026-20182, ED 26-03) against multi-site Trust / private-healthcare estate | M | H | HIGH |
| Direct ransomware deployment against Trust or private-healthcare estate (Qilin / INC Ransom / Akira) | H | H | CRITICAL |
| EPR / PACS / patient-data exfiltration leading to ICO-grade breach disclosure | M | H | HIGH |
| BEC and invoice-fraud against Trust finance / procurement teams | H | M | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities for the next reporting cycle should focus on three concurrent threads. First, edge-appliance exploitation telemetry on Citrix NetScaler, Ivanti EPMM and Palo Alto PAN-OS. Second, EPR (electronic patient record), PACS (imaging) and laboratory-information-system access patterns — anomalous bulk-export and large-scale record queries are the principal precursor signatures. Third, medical-device network segmentation enforcement and any anomalous east-west traffic between clinical and corporate VLANs.
Defend
Patch posture is the single most operationally consequential defensive action for the next reporting cycle. CVE-2026-20182 (Cisco SD-WAN, ED 26-03), CVE-2026-6973 (Ivanti EPMM), CVE-2026-0300 (PAN-OS), CVE-2026-3055 / CVE-2026-4368 (NetScaler) and CVE-2026-4670 (MOVEit Automation) are the prioritised set. Where Trusts rely on third-party pathology, imaging or managed-IT providers, request written confirmation of provider posture against the same set — Synnovis is the structural reference for why supplier patch posture matters. Apply medical-device segmentation and lateral-movement controls aggressively; treat any unmanaged clinical device as adversary-reachable and limit blast radius accordingly.
Disrupt
Disruption priorities for the next reporting cycle are concentrated in three areas. First, indicator sharing within Health-ISAC and CiSP Healthcare Trust Group — the IP Insights enrichment service should be used to support prompt indicator submission. Second, takedown coordination on phishing infrastructure spoofing NHS, Trust and private-healthcare brands. Third, supplier-cyber-assurance intelligence exchange with Trust peers around pathology, imaging and managed-IT provider posture.
10. Forward outlook
It is highly likely that ransomware against UK healthcare will continue at current tempo. It is likely that the Synnovis / Qilin disclosure tail will produce at least one further enforcement-related public disclosure within the cycle. It is likely that CISA ED 26-03 (Cisco SD-WAN) will produce at least one publicly-disclosed UK healthcare exploitation event within the next two reporting cycles. There is a realistic possibility of an opportunistic ransomware operator targeting a UK private-healthcare or imaging-services provider during the cycle, given less-publicly-defended estates post-Synnovis.
Trigger conditions warranting forecast revision: confirmed exploitation of CVE-2026-20182 against a UK Trust or private-healthcare provider (raises the vertical-risk to CRITICAL); a new pathology, imaging or laboratory-IT platform CVE published with active exploitation evidence; Qilin or successor cluster publicly claiming attribution against a UK Trust during the next reporting cycle; H-ISAC Heartbeat reporting of a novel TTP against NHS clinical estates.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC – Reports & Advisories (rolling) | NCSC | A1 |
| 2 | NCSC – Cisco Catalyst SD-WAN advisory and ED 26-03 alignment (May 2026) | NCSC / CISA | A1 |
| 3 | NCSC – Citrix NetScaler ADC / Gateway CVE-2026-3055 / CVE-2026-4368 | NCSC | A1 |
| 4 | NCSC – F5 BIG-IP Access Policy Manager unauthenticated RCE advisory | NCSC | A1 |
| 5 | NCSC – Middle East cyber posture review guidance | NCSC | A1 |
| 6 | CISA Known Exploited Vulnerabilities Catalogue (rolling) | CISA | A1 |
| 7 | CISA Alert – CVE-2026-20182 Cisco Catalyst SD-WAN Controller added to KEV (14 May 2026) | CISA | A1 |
| 8 | CISA Emergency Directive 26-03 – Mitigate Cisco SD-WAN Vulnerabilities | CISA | A1 |
| 9 | CISA Alert – Ivanti EPMM CVE-2026-6973 active exploitation | CISA | A1 |
| 10 | Check Point Research – State of Ransomware Q1 2026 | Check Point Research | B2 |
| 11 | Breachsense – April / Q1 2026 ransomware tracking | Breachsense | B2 |
| 12 | Ransomware.live – sector and group leak-site index | Ransomware.live | B2 |
| 13 | IP Insights – IP reputation and blocklist enrichment service | UK Cyber Defence | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Healthcare Threat Intelligence Briefing
Healthcare Sector Ransomware Threat Analysis, May 2025
Healthcare threat intelligence report — 27 April – 3 May 2026
The healthcare threat picture for the reporting period continues to escalate. Health-ISAC reporting flags a 55% surge in cyber incidents in 2025 with continued escalation expected in 2026.
Healthcare threat intelligence report — 4–8 May 2026
The healthcare threat picture for the reporting period continues to escalate.