Healthcare threat intelligence report — 16–22 May 2026
The reporting cycle has been shaped by Health-ISAC's continued elevation of ransomware as the \#1 threat to healthcare (455 health-sector ransomware incidents globally in their 2026 retrospective)…
- Reference: TI-2026-0522-005 (public edition)
- Sector: Healthcare
- Reporting period: 16–22 May 2026
- Issued: 22 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report assesses the threat landscape affecting the Healthcare vertical for the period 16 May 2026 to 22 May 2026. The reporting cycle has been shaped by Health-ISAC's continued elevation of ransomware as the #1 threat to healthcare (455 health-sector ransomware incidents globally in their 2026 retrospective), the West Pharmaceutical Services event during the reporting period (cross-sector healthcare-adjacent disruption), and the European hospital cybersecurity-buyer sentiment data showing 82% rate their 2026 attack concern as very-high or extreme.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware will remain the dominant materially-disruptive threat to UK and European healthcare entities through 2026, with Qilin, INC Ransom and SAFEPAY the most active health-sector specialists per Health-ISAC's 2026 retrospective. (HIGH confidence)
- It is likely that European hospital boards will continue to escalate cyber risk to the same register as clinical-safety risk through 2026, driven by direct-to-care-disruption case studies rather than data-loss penalties. (HIGH confidence)
- It is likely that at least one NHS trust will sustain a public ransomware incident with patient-safety consequences in the second half of 2026, given the steady cadence observed in the past 18 months. (MEDIUM confidence)
- There is a realistic possibility that AI-driven extortion against medical-device manufacturers will emerge as a near-term tradecraft pattern, building on the April 2026 ShinyHunters claim against a major device giant. (MEDIUM confidence)
- It is highly likely that pathology, radiology and diagnostic-laboratory supply chains will remain the highest-value disruption target inside the healthcare vertical, given the demonstrated patient-safety-incident yield (122 pathology-related safety incidents in a single UK trust per the early-2026 dataset). (HIGH confidence)
2. Sector threat landscape
The healthcare vertical's threat picture in 2026 is dominated by the Health-ISAC 2026 retrospective: 455 ransomware incidents globally targeting health organisations in the 2025 dataset, with Qilin, INC Ransom and SAFEPAY the most active health-sector specialists. Health-ISAC reported a 55% surge in cyber incidents in 2025 and characterised the 2026 outlook as one of continued escalation. European hospital cybersecurity-buyer sentiment data from May 2026 indicates 82% of 284 surveyed European hospital cyber decision-makers rate their 2026 attack concern as very-high or extreme.
Operationally, the consequential dynamic is the shift from data-loss-as-primary-impact to care-delivery-disruption-as-primary-impact. The UK trust that reported 122 pathology-related patient-safety incidents and 161,560 delayed pathology reports as of January 2026 is the canonical case study for how a ransomware incident at a healthcare adjacency translates into patient-safety harm. The London-area NHS trust ransomware event of 2024 continues to drive Health-ISAC and ENISA member discussions through 2026, with Recorded Future News documenting ongoing disruption nearly two years after the initial event.
Threat-actor focus on the vertical is consistent with Health-ISAC's annual analysis. Qilin continues to lead health-sector targeting; INC Ransom maintains a sustained healthcare focus; SAFEPAY has emerged as a credible third tier. The cross-sector ransomware groups (Akira, DragonForce, TheGentlemen) target healthcare opportunistically rather than as a primary vertical. Nation-state activity against medical-research targets remains a credible but less-visible operational risk, with Mandiant and Microsoft Threat Intelligence reporting on Chinese and Iranian APT interest in vaccine, biotech and clinical-trial data through 2025–26.
From a vulnerability perspective, the May 2026 picture is dominated by the same edge-appliance CVEs as the cross-sector view — Cisco SD-WAN, Ivanti EPMM, Trend Micro Apex One, Citrix NetScaler. Healthcare-specific concerns include the continued legacy-Windows footprint in medical-imaging and laboratory-instrument environments (which the CISA KEV refresh on 20 May 2026 — covering CVE-2008-4250, CVE-2009-1537, CVE-2009-3459, CVE-2010-0249 and CVE-2010-0806 — makes more operationally pressing) and the high-prevalence Ivanti EPMM footprint across European hospital-trust mobile fleets.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. Profiles below are repeated for each actor; established actors with no fresh activity in the reporting period are referenced briefly in Section 2 without a full profile.
| THREAT ACTOR PROFILE — Qilin (healthcare lead) | |
|---|---|
| Aliases | Agenda, Qilin.B |
| Suspected Origin | Russia |
| Suspected Sponsor | Criminal (RaaS) |
| Primary Motivation | Financial extortion / data theft |
| Sector Focus | Healthcare lead; cross-sector secondary |
| Tooling | Qilin.B encryptor (ESXi-aware), SystemBC, AnyDesk, Cobalt Strike, rclone |
| TTP Highlights | IAB-purchased VPN credentials; rapid privilege escalation; ESXi-aware encryption; double-extortion with media-friendly leak-site disclosure |
| Reporting Cycle Activity | Sustained leak-site cadence; healthcare victims continue to feature in disclosures |
| Confidence | HIGH |
| Admiralty | A2 |
| Reference | Refs 1, 4 |
| THREAT ACTOR PROFILE — INC Ransom | |
|---|---|
| Aliases | INC Ransomware |
| Suspected Origin | Russian-speaking criminal milieu |
| Suspected Sponsor | Criminal (RaaS) |
| Primary Motivation | Financial extortion / data theft |
| Sector Focus | Healthcare-heavy victim mix |
| Tooling | INC encryptor; AnyDesk; PowerShell-loaded post-exploitation toolkit; data theft via rclone / MEGAcmd |
| TTP Highlights | Selective post-compromise targeting; emphasis on patient data theft for extortion leverage; double-extortion |
| Reporting Cycle Activity | Sustained healthcare-sector cadence through Q1 2026 per Health-ISAC |
| Confidence | MEDIUM-HIGH |
| Admiralty | B2 |
| Reference | Ref 1 |
| THREAT ACTOR PROFILE — SAFEPAY | |
|---|---|
| Aliases | — |
| Suspected Origin | Russian-speaking criminal milieu |
| Suspected Sponsor | Criminal (RaaS) |
| Primary Motivation | Financial extortion |
| Sector Focus | Healthcare and adjacent professional services |
| Tooling | SAFEPAY encryptor; commodity hands-on-keyboard toolkit |
| TTP Highlights | Less-mature TTP profile than Qilin / INC; positioning as a third-tier healthcare-focused operator |
| Reporting Cycle Activity | Emerging through Q1 2026 per Health-ISAC |
| Confidence | MEDIUM |
| Admiralty | C3 |
| Reference | Ref 1 |
| THREAT ACTOR PROFILE — ShinyHunters (medical-device extortion subset) | |
|---|---|
| Aliases | — |
| Suspected Origin | Mixed criminal milieu |
| Suspected Sponsor | Criminal (extortion cluster) |
| Primary Motivation | Financial — pure data extortion |
| Sector Focus | Cross-sector with selective medical-device interest |
| Tooling | Data-theft toolkit (rclone, MEGAcmd); leak-site for staged disclosure |
| TTP Highlights | Pure data extortion against high-leverage targets; April 2026 claim against a major medical-device manufacturer is the canonical case |
| Reporting Cycle Activity | No new headline healthcare claim during the reporting period, but continued residual activity |
| Confidence | MEDIUM |
| Admiralty | B3 |
| Reference | Ref 7 |
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviour column summarises the activity in operational terms suitable for use in detection engineering and threat hunting.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1078.004 | Valid Accounts: Cloud | IAB-purchased VPN / M365 credentials into hospital-trust tenants. | HIGH |
| Initial Access | T1190 | Exploit Public-Facing Application | Exploitation of edge appliances (Cisco SD-WAN, Citrix NetScaler, Ivanti EPMM) against hospital perimeter estates. | HIGH |
| Initial Access | T1566.001 | Spear-phishing Attachment | Spear-phishing of clinical, administrative and procurement staff with healthcare-themed lures. | HIGH |
| Execution | T1059.001 | PowerShell | Encoded loaders for ransomware staging within compromised infrastructure. | MEDIUM |
| Persistence | T1543.003 | Create or Modify System Process: Windows Service | New attacker-owned services for persistence inside hospital-trust application servers. | MEDIUM |
| Credential Access | T1003 | OS Credential Dumping | comsvcs.dll MiniDump / Mimikatz against hospital-trust domain controllers. | MEDIUM |
| Lateral Movement | T1021.001 | Remote Services: RDP | Pivot into ESXi management of clinical-system virtualised estate and into PACS / RIS / LIS estate. | HIGH |
| Collection | T1213.002 | Data from Information Repositories | Bulk download of pathology / radiology / EPR data prior to encryption. | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / MEGAcmd / AzCopy for staged patient-data theft. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Qilin.B / INC / SAFEPAY ESXi-aware encryption against hospital virtualised estate. | HIGH |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 18 May 2026 | West Pharmaceutical Services (healthcare-adjacent) | Unattributed ransomware | Disruption to shipping, manufacturing and shared-service functions; pharma supply-chain operational impact. | Ref 12 |
| Reporting period | Continued Qilin / INC / SAFEPAY leak-site postings | Various RaaS | Sustained healthcare-sector victim cadence per Health-ISAC tracking. | Ref 1 |
| Recent prior (Apr 2026) | Medical-device manufacturer (un-named) | ShinyHunters extortion claim | Pure data extortion against major device manufacturer. | Ref 7 |
| Recent prior | UK NHS trust (London area) | Unattributed (historic ref) | Multi-month operational disruption with documented patient-safety consequences; 122 pathology-related incidents at one trust as of Jan 2026. | Ref 10 |
| Reporting period | Multiple Akira healthcare victims | Akira | Healthcare-relevant victims in the 30+ posted on 20 May leak update. | Ref 11 |
| Reporting period | Multiple TheGentlemen healthcare victims | TheGentlemen | Healthcare-adjacent victims appearing in 424-victim leak-site total. | Ref 6 |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of the affected product in client estates, and the operational exposure of the typical deployment.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20182 | Cisco Catalyst SD-WAN | 10.0 | Yes | Active ITW | Patch immediately. |
| CVE-2026-6973 | Ivanti EPMM (on-prem) | 7.2 | Yes | Active ITW | Patch; rotate pre-Feb 2026 admin credentials; high prevalence in European hospital-trust mobile fleets. |
| CVE-2026-34926 | Trend Micro Apex One (on-prem) | 8.7 | Yes | Active ITW | Apply fix; review Apex One console exposure across hospital-trust Windows estate. |
| CVE-2026-3055 / CVE-2026-4368 | Citrix NetScaler | 9.3 / 8.6 | Yes | Active ITW | Apply Citrix-supplied builds; force-rotate session keys. |
| CVE-2026-41091 / 45498 | Microsoft Defender | 7.8 / 6.5 | Yes | Confirmed | Apply May 2026 Patch Tuesday roll-up. |
| CVE-2008-4250 / 2009-1537 / 2009-3459 / 2010-0249 / 2010-0806 | Legacy Microsoft / Adobe | various | Yes | Active ITW (KEV refresh 20 May 2026) | Audit hospital legacy Windows estate (PACS / RIS / LIS / medical-imaging workstations); isolate, virtualise or decommission immediately. |
| CVE-2026-31431 | Linux Kernel | 7.0 | Yes | Active ITW | Apply distribution-supplied kernel. |
| Sector-specific | Insecure DICOM / HL7 interface exposure | varies | n/a | Recurring | Audit DICOM / HL7 endpoints for unencrypted exposure; segment medical imaging and lab-instrument estates from corporate IT. |
| Sector-specific | Medical-device firmware update channels | varies | n/a | Recurring | Audit medical-device firmware-update integrity; ensure devices on out-of-support firmware are tracked against MHRA / FDA safety registers. |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the strength of the underlying corroboration and the lifetime of the indicator type.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IP | 87.103.126.54 | 12 May 2026 | HIGH | SSH/CMS brute-force; Vodafone PT; IP Insights threat_score 100; egress-deny candidate. |
| Domain | patient-portal-secure[.]net | Reporting period | MEDIUM | Hospital-trust patient-portal impersonation pattern. |
| Domain | healthcare-mfa-reset[.]com | Reporting period | MEDIUM | Identity-provider impersonation pattern aimed at hospital-trust M365 tenants. |
| TTP | OAuth consent-phishing for M365 mailbox.read scope | Recurring | MEDIUM | Block third-party consent grants without admin review. |
| TTP | ESXi-aware encryption following IAB credential reuse | Recurring | HIGH | Operational pattern shared by Qilin, INC and SAFEPAY against hospital estates. |
| Hash (SHA-256) | INC encryptor variant (redacted) | Reporting period | MEDIUM | Deploy YARA-based detection alongside existing INC family ruleset. |
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating reflects the product of likelihood and impact over the next reporting cycle.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| Ransomware compromise of clinical virtualised estate | HIGH | HIGH | CRITICAL |
| Pathology / radiology / LIS disruption with patient-safety consequences | MEDIUM-HIGH | CRITICAL | CRITICAL |
| Medical-device or research-data pure extortion (ShinyHunters-style) | MEDIUM | HIGH | HIGH |
| Legacy-Windows medical-imaging exploitation | MEDIUM | MEDIUM-HIGH | HIGH |
| Patient-data theft followed by leak-site disclosure | HIGH | HIGH | CRITICAL |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment within the next reporting cycle and should be prioritised in line with the risk assessment in Section 8.
Detect
- Clinical-system telemetry: instrument PACS / RIS / LIS authentication logs for failed-then-success patterns, geo-anomalies, and impossible-travel for any clinical or admin user.
- Hospital identity-provider telemetry: alert on new device registration on clinical admin accounts, OAuth consent grants from non-admin users, and impossible-travel on any consultant / registrar account.
- Medical-device firmware-integrity telemetry: where the device supports it, alert on any firmware-update package signed by a non-vendor key or any out-of-cycle firmware change.
Defend
- Patch Cisco SD-WAN, Ivanti EPMM, Trend Micro Apex One, Citrix NetScaler and apply May 2026 Microsoft Patch Tuesday roll-up across the hospital-trust estate.
- Audit and segment legacy-Windows medical-imaging and laboratory-instrument estates; isolate any device running on the CVE-2008-4250 / 2009-1537 / 2009-3459 / 2010-0249 / 2010-0806 KEV refresh footprint behind a hardened reverse proxy or decommission.
- Enforce phishing-resistant MFA on all M365 / identity-provider admin accounts and on all PACS / RIS / LIS admin accounts.
- Validate offline / immutable backup for clinical systems against an explicit ESXi-aware ransomware scenario with a patient-safety-impact cell on the table.
Disrupt
- Subscribe to Health-ISAC and contribute observed indicators back through the Heartbeat feed channel.
- Push indicators in Section 7 into preventive controls via the ipinsights.io TAXII 2.1 endpoint.
- Tabletop a pathology-or-radiology-disruption scenario with the clinical-governance leadership; the patient-safety-incident yield of a single pathology outage is the right operational test for 2026.
10. Forward outlook
It is highly likely that healthcare ransomware will remain at or above 2025 frequency through 2026, with Qilin, INC Ransom and SAFEPAY the principal health-sector specialists. (HIGH confidence)
It is likely that at least one further UK NHS trust will sustain a publicly-disclosed ransomware event with patient-safety consequences before end of 2026. (MEDIUM confidence)
Trigger conditions warranting forecast revision: confirmed exploitation of CVE-2026-6973 / CVE-2026-20182 against a UK NHS trust; emergence of a nation-state-attributed campaign against UK medical-research entities; or a publicly-disclosed medical-device firmware integrity compromise.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence from multiple reliable sources with limited ambiguity; MEDIUM indicates partially-corroborated evidence with some logical inference; LOW indicates limited or fragmentary evidence requiring careful onward use. Estimative language follows the conventions of UK intelligence writing — "almost certainly", "highly likely", "likely", "realistic possibility", "unlikely", "highly unlikely" — and is used in preference to numerical probability bands.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for the convenience of recipients.
| Source | Reliability | Information | Credibility |
|---|---|---|---|
| A — Completely reliable | Demonstrated repeated reliability | 1 — Confirmed | Corroborated by independent sources |
| B — Usually reliable | Reliable on most occasions | 2 — Probably true | Logical, consistent, partially corroborated |
| C — Fairly reliable | Sometimes reliable | 3 — Possibly true | Reasonably logical, agrees with some information |
| D — Not usually reliable | Limited prior accuracy | 4 — Doubtful | Possible but lacks logic or corroboration |
| E — Unreliable | History of inaccuracy | 5 — Improbable | Contradicts other reporting |
| F — Cannot be judged | No basis for evaluation | 6 — Cannot be judged | Cannot be assessed |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System (see Section 11).
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | Health-ISAC 2026 Annual Threat Report | Health-ISAC | A1 |
| 2 | Health-ISAC 55% surge in 2025 incidents (2026 outlook) | Industrial Cyber | A2 |
| 3 | Health-ISAC Heartbeat — ransomware / VPN-exploit surge | Industrial Cyber | A2 |
| 4 | Q1 2026 Ransomware Retrospective | Check Point Research | B2 |
| 5 | Europe's Hospital Cyber Risk — Black Book Study (HIMSS26 Europe) | Access Newswire; Black Book | B2 |
| 6 | TheGentlemen leak-site cadence and SystemBC C2 revelations | The Hacker News; ransomware.live | B2 |
| 7 | April 2026 — supply-chain & ShinyHunters extortion against medical-device giant | ENISA; cm-alliance.com; TechCrunch (April 2026) | B2 |
| 8 | CISA / NCSC-UK joint advisory on CVE-2026-20182 | CISA; NCSC-UK; NSA; ACSC; CCCS | A1 |
| 9 | Ivanti EPMM May 2026 Security Update | Ivanti; Help Net Security; SocRadar | A2 |
| 10 | London-area NHS trust ransomware — ongoing disruption | The Record by Recorded Future | A2 |
| 11 | Akira drops 30 victims in one day | SecurityWeek; The Record | A2 |
| 12 | West Pharmaceutical Services ransomware (cross-sector) | SecurityWeek; Hendry Adrian Daily Recap | B2 |
| 13 | CISA KEV refresh — legacy Microsoft / Adobe CVEs (20 May 2026) | CISA | A1 |
| 14 | ipinsights.io enrichment & blocklist data | ipinsights.io | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Healthcare Threat Intelligence Briefing
Healthcare Sector Ransomware Threat Analysis, May 2025
Healthcare threat intelligence report — 27 April – 3 May 2026
The healthcare threat picture for the reporting period continues to escalate. Health-ISAC reporting flags a 55% surge in cyber incidents in 2025 with continued escalation expected in 2026.
Healthcare threat intelligence report — 4–8 May 2026
The healthcare threat picture for the reporting period continues to escalate.