SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Healthcare threat intelligence report — 16–22 May 2026

The reporting cycle has been shaped by Health-ISAC's continued elevation of ransomware as the \#1 threat to healthcare (455 health-sector ransomware incidents globally in their 2026 retrospective)…

  • Reference: TI-2026-0522-005 (public edition)
  • Sector: Healthcare
  • Reporting period: 16–22 May 2026
  • Issued: 22 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report assesses the threat landscape affecting the Healthcare vertical for the period 16 May 2026 to 22 May 2026. The reporting cycle has been shaped by Health-ISAC's continued elevation of ransomware as the #1 threat to healthcare (455 health-sector ransomware incidents globally in their 2026 retrospective), the West Pharmaceutical Services event during the reporting period (cross-sector healthcare-adjacent disruption), and the European hospital cybersecurity-buyer sentiment data showing 82% rate their 2026 attack concern as very-high or extreme.

Key Judgements

The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  • It is highly likely that ransomware will remain the dominant materially-disruptive threat to UK and European healthcare entities through 2026, with Qilin, INC Ransom and SAFEPAY the most active health-sector specialists per Health-ISAC's 2026 retrospective. (HIGH confidence)
  • It is likely that European hospital boards will continue to escalate cyber risk to the same register as clinical-safety risk through 2026, driven by direct-to-care-disruption case studies rather than data-loss penalties. (HIGH confidence)
  • It is likely that at least one NHS trust will sustain a public ransomware incident with patient-safety consequences in the second half of 2026, given the steady cadence observed in the past 18 months. (MEDIUM confidence)
  • There is a realistic possibility that AI-driven extortion against medical-device manufacturers will emerge as a near-term tradecraft pattern, building on the April 2026 ShinyHunters claim against a major device giant. (MEDIUM confidence)
  • It is highly likely that pathology, radiology and diagnostic-laboratory supply chains will remain the highest-value disruption target inside the healthcare vertical, given the demonstrated patient-safety-incident yield (122 pathology-related safety incidents in a single UK trust per the early-2026 dataset). (HIGH confidence)

2. Sector threat landscape

The healthcare vertical's threat picture in 2026 is dominated by the Health-ISAC 2026 retrospective: 455 ransomware incidents globally targeting health organisations in the 2025 dataset, with Qilin, INC Ransom and SAFEPAY the most active health-sector specialists. Health-ISAC reported a 55% surge in cyber incidents in 2025 and characterised the 2026 outlook as one of continued escalation. European hospital cybersecurity-buyer sentiment data from May 2026 indicates 82% of 284 surveyed European hospital cyber decision-makers rate their 2026 attack concern as very-high or extreme.

Operationally, the consequential dynamic is the shift from data-loss-as-primary-impact to care-delivery-disruption-as-primary-impact. The UK trust that reported 122 pathology-related patient-safety incidents and 161,560 delayed pathology reports as of January 2026 is the canonical case study for how a ransomware incident at a healthcare adjacency translates into patient-safety harm. The London-area NHS trust ransomware event of 2024 continues to drive Health-ISAC and ENISA member discussions through 2026, with Recorded Future News documenting ongoing disruption nearly two years after the initial event.

Threat-actor focus on the vertical is consistent with Health-ISAC's annual analysis. Qilin continues to lead health-sector targeting; INC Ransom maintains a sustained healthcare focus; SAFEPAY has emerged as a credible third tier. The cross-sector ransomware groups (Akira, DragonForce, TheGentlemen) target healthcare opportunistically rather than as a primary vertical. Nation-state activity against medical-research targets remains a credible but less-visible operational risk, with Mandiant and Microsoft Threat Intelligence reporting on Chinese and Iranian APT interest in vaccine, biotech and clinical-trial data through 2025–26.

From a vulnerability perspective, the May 2026 picture is dominated by the same edge-appliance CVEs as the cross-sector view — Cisco SD-WAN, Ivanti EPMM, Trend Micro Apex One, Citrix NetScaler. Healthcare-specific concerns include the continued legacy-Windows footprint in medical-imaging and laboratory-instrument environments (which the CISA KEV refresh on 20 May 2026 — covering CVE-2008-4250, CVE-2009-1537, CVE-2009-3459, CVE-2010-0249 and CVE-2010-0806 — makes more operationally pressing) and the high-prevalence Ivanti EPMM footprint across European hospital-trust mobile fleets.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. Profiles below are repeated for each actor; established actors with no fresh activity in the reporting period are referenced briefly in Section 2 without a full profile.

THREAT ACTOR PROFILE — Qilin (healthcare lead)
AliasesAgenda, Qilin.B
Suspected OriginRussia
Suspected SponsorCriminal (RaaS)
Primary MotivationFinancial extortion / data theft
Sector FocusHealthcare lead; cross-sector secondary
ToolingQilin.B encryptor (ESXi-aware), SystemBC, AnyDesk, Cobalt Strike, rclone
TTP HighlightsIAB-purchased VPN credentials; rapid privilege escalation; ESXi-aware encryption; double-extortion with media-friendly leak-site disclosure
Reporting Cycle ActivitySustained leak-site cadence; healthcare victims continue to feature in disclosures
ConfidenceHIGH
AdmiraltyA2
ReferenceRefs 1, 4
THREAT ACTOR PROFILE — INC Ransom
AliasesINC Ransomware
Suspected OriginRussian-speaking criminal milieu
Suspected SponsorCriminal (RaaS)
Primary MotivationFinancial extortion / data theft
Sector FocusHealthcare-heavy victim mix
ToolingINC encryptor; AnyDesk; PowerShell-loaded post-exploitation toolkit; data theft via rclone / MEGAcmd
TTP HighlightsSelective post-compromise targeting; emphasis on patient data theft for extortion leverage; double-extortion
Reporting Cycle ActivitySustained healthcare-sector cadence through Q1 2026 per Health-ISAC
ConfidenceMEDIUM-HIGH
AdmiraltyB2
ReferenceRef 1
THREAT ACTOR PROFILE — SAFEPAY
Aliases
Suspected OriginRussian-speaking criminal milieu
Suspected SponsorCriminal (RaaS)
Primary MotivationFinancial extortion
Sector FocusHealthcare and adjacent professional services
ToolingSAFEPAY encryptor; commodity hands-on-keyboard toolkit
TTP HighlightsLess-mature TTP profile than Qilin / INC; positioning as a third-tier healthcare-focused operator
Reporting Cycle ActivityEmerging through Q1 2026 per Health-ISAC
ConfidenceMEDIUM
AdmiraltyC3
ReferenceRef 1
THREAT ACTOR PROFILE — ShinyHunters (medical-device extortion subset)
Aliases
Suspected OriginMixed criminal milieu
Suspected SponsorCriminal (extortion cluster)
Primary MotivationFinancial — pure data extortion
Sector FocusCross-sector with selective medical-device interest
ToolingData-theft toolkit (rclone, MEGAcmd); leak-site for staged disclosure
TTP HighlightsPure data extortion against high-leverage targets; April 2026 claim against a major medical-device manufacturer is the canonical case
Reporting Cycle ActivityNo new headline healthcare claim during the reporting period, but continued residual activity
ConfidenceMEDIUM
AdmiraltyB3
ReferenceRef 7

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviour column summarises the activity in operational terms suitable for use in detection engineering and threat hunting.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConf.
Initial AccessT1078.004Valid Accounts: CloudIAB-purchased VPN / M365 credentials into hospital-trust tenants.HIGH
Initial AccessT1190Exploit Public-Facing ApplicationExploitation of edge appliances (Cisco SD-WAN, Citrix NetScaler, Ivanti EPMM) against hospital perimeter estates.HIGH
Initial AccessT1566.001Spear-phishing AttachmentSpear-phishing of clinical, administrative and procurement staff with healthcare-themed lures.HIGH
ExecutionT1059.001PowerShellEncoded loaders for ransomware staging within compromised infrastructure.MEDIUM
PersistenceT1543.003Create or Modify System Process: Windows ServiceNew attacker-owned services for persistence inside hospital-trust application servers.MEDIUM
Credential AccessT1003OS Credential Dumpingcomsvcs.dll MiniDump / Mimikatz against hospital-trust domain controllers.MEDIUM
Lateral MovementT1021.001Remote Services: RDPPivot into ESXi management of clinical-system virtualised estate and into PACS / RIS / LIS estate.HIGH
CollectionT1213.002Data from Information RepositoriesBulk download of pathology / radiology / EPR data prior to encryption.HIGH
ExfiltrationT1567.002Exfiltration to Cloud Storagerclone / MEGAcmd / AzCopy for staged patient-data theft.HIGH
ImpactT1486Data Encrypted for ImpactQilin.B / INC / SAFEPAY ESXi-aware encryption against hospital virtualised estate.HIGH

5. Notable incidents and campaigns

DateAffected Org / Sub-SectorSuspected AttributionImpact SummaryReference
18 May 2026West Pharmaceutical Services (healthcare-adjacent)Unattributed ransomwareDisruption to shipping, manufacturing and shared-service functions; pharma supply-chain operational impact.Ref 12
Reporting periodContinued Qilin / INC / SAFEPAY leak-site postingsVarious RaaSSustained healthcare-sector victim cadence per Health-ISAC tracking.Ref 1
Recent prior (Apr 2026)Medical-device manufacturer (un-named)ShinyHunters extortion claimPure data extortion against major device manufacturer.Ref 7
Recent priorUK NHS trust (London area)Unattributed (historic ref)Multi-month operational disruption with documented patient-safety consequences; 122 pathology-related incidents at one trust as of Jan 2026.Ref 10
Reporting periodMultiple Akira healthcare victimsAkiraHealthcare-relevant victims in the 30+ posted on 20 May leak update.Ref 11
Reporting periodMultiple TheGentlemen healthcare victimsTheGentlemenHealthcare-adjacent victims appearing in 424-victim leak-site total.Ref 6

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of the affected product in client estates, and the operational exposure of the typical deployment.

CVE IDAffected ProductCVSSKEVActive ExploitationRecommended Action
CVE-2026-20182Cisco Catalyst SD-WAN10.0YesActive ITWPatch immediately.
CVE-2026-6973Ivanti EPMM (on-prem)7.2YesActive ITWPatch; rotate pre-Feb 2026 admin credentials; high prevalence in European hospital-trust mobile fleets.
CVE-2026-34926Trend Micro Apex One (on-prem)8.7YesActive ITWApply fix; review Apex One console exposure across hospital-trust Windows estate.
CVE-2026-3055 / CVE-2026-4368Citrix NetScaler9.3 / 8.6YesActive ITWApply Citrix-supplied builds; force-rotate session keys.
CVE-2026-41091 / 45498Microsoft Defender7.8 / 6.5YesConfirmedApply May 2026 Patch Tuesday roll-up.
CVE-2008-4250 / 2009-1537 / 2009-3459 / 2010-0249 / 2010-0806Legacy Microsoft / AdobevariousYesActive ITW (KEV refresh 20 May 2026)Audit hospital legacy Windows estate (PACS / RIS / LIS / medical-imaging workstations); isolate, virtualise or decommission immediately.
CVE-2026-31431Linux Kernel7.0YesActive ITWApply distribution-supplied kernel.
Sector-specificInsecure DICOM / HL7 interface exposurevariesn/aRecurringAudit DICOM / HL7 endpoints for unencrypted exposure; segment medical imaging and lab-instrument estates from corporate IT.
Sector-specificMedical-device firmware update channelsvariesn/aRecurringAudit medical-device firmware-update integrity; ensure devices on out-of-support firmware are tracked against MHRA / FDA safety registers.

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the strength of the underlying corroboration and the lifetime of the indicator type.

TypeIndicatorFirst SeenConf.Notes
IP87.103.126.5412 May 2026HIGHSSH/CMS brute-force; Vodafone PT; IP Insights threat_score 100; egress-deny candidate.
Domainpatient-portal-secure[.]netReporting periodMEDIUMHospital-trust patient-portal impersonation pattern.
Domainhealthcare-mfa-reset[.]comReporting periodMEDIUMIdentity-provider impersonation pattern aimed at hospital-trust M365 tenants.
TTPOAuth consent-phishing for M365 mailbox.read scopeRecurringMEDIUMBlock third-party consent grants without admin review.
TTPESXi-aware encryption following IAB credential reuseRecurringHIGHOperational pattern shared by Qilin, INC and SAFEPAY against hospital estates.
Hash (SHA-256)INC encryptor variant (redacted)Reporting periodMEDIUMDeploy YARA-based detection alongside existing INC family ruleset.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating reflects the product of likelihood and impact over the next reporting cycle.

Threat ScenarioLikelihoodImpactComposite
Ransomware compromise of clinical virtualised estateHIGHHIGHCRITICAL
Pathology / radiology / LIS disruption with patient-safety consequencesMEDIUM-HIGHCRITICALCRITICAL
Medical-device or research-data pure extortion (ShinyHunters-style)MEDIUMHIGHHIGH
Legacy-Windows medical-imaging exploitationMEDIUMMEDIUM-HIGHHIGH
Patient-data theft followed by leak-site disclosureHIGHHIGHCRITICAL

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment within the next reporting cycle and should be prioritised in line with the risk assessment in Section 8.

Detect

  • Clinical-system telemetry: instrument PACS / RIS / LIS authentication logs for failed-then-success patterns, geo-anomalies, and impossible-travel for any clinical or admin user.
  • Hospital identity-provider telemetry: alert on new device registration on clinical admin accounts, OAuth consent grants from non-admin users, and impossible-travel on any consultant / registrar account.
  • Medical-device firmware-integrity telemetry: where the device supports it, alert on any firmware-update package signed by a non-vendor key or any out-of-cycle firmware change.

Defend

  • Patch Cisco SD-WAN, Ivanti EPMM, Trend Micro Apex One, Citrix NetScaler and apply May 2026 Microsoft Patch Tuesday roll-up across the hospital-trust estate.
  • Audit and segment legacy-Windows medical-imaging and laboratory-instrument estates; isolate any device running on the CVE-2008-4250 / 2009-1537 / 2009-3459 / 2010-0249 / 2010-0806 KEV refresh footprint behind a hardened reverse proxy or decommission.
  • Enforce phishing-resistant MFA on all M365 / identity-provider admin accounts and on all PACS / RIS / LIS admin accounts.
  • Validate offline / immutable backup for clinical systems against an explicit ESXi-aware ransomware scenario with a patient-safety-impact cell on the table.

Disrupt

  • Subscribe to Health-ISAC and contribute observed indicators back through the Heartbeat feed channel.
  • Push indicators in Section 7 into preventive controls via the ipinsights.io TAXII 2.1 endpoint.
  • Tabletop a pathology-or-radiology-disruption scenario with the clinical-governance leadership; the patient-safety-incident yield of a single pathology outage is the right operational test for 2026.

10. Forward outlook

It is highly likely that healthcare ransomware will remain at or above 2025 frequency through 2026, with Qilin, INC Ransom and SAFEPAY the principal health-sector specialists. (HIGH confidence)

It is likely that at least one further UK NHS trust will sustain a publicly-disclosed ransomware event with patient-safety consequences before end of 2026. (MEDIUM confidence)

Trigger conditions warranting forecast revision: confirmed exploitation of CVE-2026-6973 / CVE-2026-20182 against a UK NHS trust; emergence of a nation-state-attributed campaign against UK medical-research entities; or a publicly-disclosed medical-device firmware integrity compromise.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence from multiple reliable sources with limited ambiguity; MEDIUM indicates partially-corroborated evidence with some logical inference; LOW indicates limited or fragmentary evidence requiring careful onward use. Estimative language follows the conventions of UK intelligence writing — "almost certainly", "highly likely", "likely", "realistic possibility", "unlikely", "highly unlikely" — and is used in preference to numerical probability bands.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for the convenience of recipients.

SourceReliabilityInformationCredibility
A — Completely reliableDemonstrated repeated reliability1 — ConfirmedCorroborated by independent sources
B — Usually reliableReliable on most occasions2 — Probably trueLogical, consistent, partially corroborated
C — Fairly reliableSometimes reliable3 — Possibly trueReasonably logical, agrees with some information
D — Not usually reliableLimited prior accuracy4 — DoubtfulPossible but lacks logic or corroboration
E — UnreliableHistory of inaccuracy5 — ImprobableContradicts other reporting
F — Cannot be judgedNo basis for evaluation6 — Cannot be judgedCannot be assessed

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System (see Section 11).

Source / TitlePublisherAdmiralty
1Health-ISAC 2026 Annual Threat ReportHealth-ISACA1
2Health-ISAC 55% surge in 2025 incidents (2026 outlook)Industrial CyberA2
3Health-ISAC Heartbeat — ransomware / VPN-exploit surgeIndustrial CyberA2
4Q1 2026 Ransomware RetrospectiveCheck Point ResearchB2
5Europe's Hospital Cyber Risk — Black Book Study (HIMSS26 Europe)Access Newswire; Black BookB2
6TheGentlemen leak-site cadence and SystemBC C2 revelationsThe Hacker News; ransomware.liveB2
7April 2026 — supply-chain & ShinyHunters extortion against medical-device giantENISA; cm-alliance.com; TechCrunch (April 2026)B2
8CISA / NCSC-UK joint advisory on CVE-2026-20182CISA; NCSC-UK; NSA; ACSC; CCCSA1
9Ivanti EPMM May 2026 Security UpdateIvanti; Help Net Security; SocRadarA2
10London-area NHS trust ransomware — ongoing disruptionThe Record by Recorded FutureA2
11Akira drops 30 victims in one daySecurityWeek; The RecordA2
12West Pharmaceutical Services ransomware (cross-sector)SecurityWeek; Hendry Adrian Daily RecapB2
13CISA KEV refresh — legacy Microsoft / Adobe CVEs (20 May 2026)CISAA1
14ipinsights.io enrichment & blocklist dataipinsights.ioB2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.