Healthcare threat intelligence report — 30 May – 5 June 2026
The healthcare collection picture this week has been shaped by the Health-ISAC 2026 threat-landscape report's continuing emphasis on Qilin, INC Ransom and SAFEPAY as the most active groups targeting health entities, with AI-enabled attack tactics flagged as the number-one concern for the year.
- Reference: TI-2026-0605-005 (public edition)
- Sector: Healthcare
- Reporting period: 30 May – 5 June 2026
- Issued: 5 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The healthcare collection picture this week has been shaped by the Health-ISAC 2026 threat-landscape report's continuing emphasis on Qilin, INC Ransom and SAFEPAY as the most active groups targeting health entities, with AI-enabled attack tactics flagged as the number-one concern for the year. The continuing fallout from the 2025 NHS-supplier incidents (DXS International, Synnovis legacy issues, Barts Health legal action) continues to define the UK sector loss narrative. The Android Framework integer-overflow vulnerability CVE-2025-48595 (KEV 02 June) is acutely relevant given the prevalence of Android-based clinical and patient-facing handsets in NHS and private-healthcare estates.
Perimeter scrubbing was dominated by sustained brute-force pressure from the standing IP Insights 'critical' tail - none successful. The continuing surge in Health-ISAC-reported VPN-exploit activity and ransomware against healthcare systems means that the sector continues to carry the highest composite risk rating in this report cycle.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that Qilin, INC Ransom and SAFEPAY will continue to dominate ransomware activity against UK and EU healthcare entities over the next reporting cycle, with consequences for patient care, regulatory exposure and supplier integrity. (HIGH confidence)
- It is likely that the Android Framework integer-overflow CVE-2025-48595 will be exploited against clinical or patient-facing Android handsets in the next reporting cycle, with consequences ranging from credential-theft to data exfiltration from MDM-managed devices. (MEDIUM-HIGH confidence)
- It is highly likely that VPN-credential exploitation against healthcare-supplier estates will continue at the elevated cadence reported in Health-ISAC's Heartbeat advisories, with Akira and Qilin as the dominant beneficiaries. (HIGH confidence)
- It is highly likely that AI-enabled social engineering - including deepfake voice and synthetic-identity bypass of caller-verification - will continue to grow as a fraud and credential-theft vector against NHS-supplier and private-healthcare contact-centres. (HIGH confidence)
- It is a realistic possibility that the BeyondTrust ransomware-risk pattern flagged by Health-ISAC will produce at least one publicly-disclosed UK healthcare event in the next two cycles. (MEDIUM confidence)
2. Sector threat landscape
Healthcare continues to carry the highest composite-risk rating among the verticals in this report cycle on account of the combination of operational consequence (patient-care disruption), regulatory exposure (NHS DSP Toolkit, ICO, CQC), supplier-chain dependency and a target population that historically has lagged in detection and response maturity. The Health-ISAC 2026 threat-landscape report tracks 455 ransomware incidents globally targeting health organisations in 2025, with Qilin, INC Ransom and SAFEPAY as the dominant groups.
Edge-appliance and VPN-credential exposure is the principal initial-access route. Health-ISAC Heartbeat advisories have flagged continuing exploitation of Fortinet, Citrix and Cisco VPN/edge appliances against healthcare-supplier estates.
Mobile-device exposure is acutely relevant this cycle. The Android Framework integer-overflow CVE-2025-48595, added to KEV on 02 June, is under limited targeted exploitation per Google's confirmation. NHS-supplier and private-healthcare estates running MDM-managed Android handsets - including clinical-staff devices and patient-facing kiosks - should treat this as a high-priority remediation. The CVE-2026-33825 Microsoft Defender BlueHammer LPE chain has direct relevance to Windows endpoint estates supporting clinical workstations.
AI-enabled threat tactics are the number-one concern flagged by Health-ISAC's executive survey for 2026. Deepfake voice impersonation of clinical staff for caller-verification bypass at NHS-supplier contact-centres, synthetic-identity onboarding of fraudulent contractors and LLM-authored spear-phishing of finance and procurement functions are all observed patterns; the marginal cost of these attacks has fallen sharply through the past 12 months.
Perimeter scrubbing handled sustained brute-force pressure from the standing IP Insights 'critical' tail - none successful.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Qilin (a.k.a. Agenda, Qilin.B)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russia
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion / data theft
- Sector Targeting: Cross-sector with sustained Healthcare relevance.
- Geographic Focus: Global; UK, EU, US, ANZ
- Signature TTPs: VPN-credential IAB initial access; ESXi-aware encryptor; double-extortion; healthcare-supplier targeting
- Tooling / Malware Families: Qilin.B encryptor; SystemBC, AnyDesk, rclone
- Recent Activity: 101 victims posted in May 2026; Health-ISAC continues to flag Qilin as one of three most-active groups against the health sector.
- Assessed Threat to Vertical: HIGH - Admiralty A2.
- Analytic Confidence: HIGH
INC Ransom
- Aliases: GOLD IONIC; Vanir Group successor lineage
- Suspected Origin: Unattributed (likely Russian-speaking)
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion / data theft
- Sector Targeting: Cross-sector with sustained Healthcare relevance.
- Geographic Focus: Global; sustained UK and US healthcare pattern
- Signature TTPs: Edge-appliance exploitation; rapid affiliate cycle; double-extortion
- Tooling / Malware Families: INC encryptor; SystemBC; Cobalt Strike
- Recent Activity: Health-ISAC 2026 report cites INC Ransom as one of three most-active groups against the health sector.
- Assessed Threat to Vertical: HIGH for healthcare; Admiralty A2.
- Analytic Confidence: HIGH
SAFEPAY
- Aliases: -
- Suspected Origin: Unattributed
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion
- Sector Targeting: Cross-sector with sustained Healthcare relevance.
- Geographic Focus: Global; sustained healthcare interest
- Signature TTPs: Phishing -> IAB hand-off -> ESXi mass-encryption
- Tooling / Malware Families: SAFEPAY encryptor; SystemBC
- Recent Activity: Health-ISAC 2026 report flags SAFEPAY among three most-active groups against the health sector.
- Assessed Threat to Vertical: HIGH for healthcare; Admiralty A2.
- Analytic Confidence: MEDIUM-HIGH
Akira
- Aliases: -
- Suspected Origin: Russia / CIS criminal milieu
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion
- Sector Targeting: Cross-sector with sustained Healthcare relevance.
- Geographic Focus: Cross-sector, global; sustained healthcare pattern
- Signature TTPs: VPN initial access (SonicWall, Cisco AnyConnect); rapid lateral via RDP; Rust encryptor
- Tooling / Malware Families: Akira / Megazord encryptors; Cobalt Strike; rclone
- Recent Activity: 52 victims posted in May 2026; H-ISAC and CISA / AHA joint warning on evolving Akira threat.
- Assessed Threat to Vertical: HIGH - Admiralty A2.
- Analytic Confidence: HIGH
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Fortinet EMS (CVE-2026-35616); Cisco SD-WAN (CVE-2026-20182); Exchange OWA (CVE-2026-42897); Health-ISAC-reported VPN exploits. | HIGH |
| Initial Access | T1133 | External Remote Services | Akira VPN-credential exploitation against healthcare-supplier perimeters. | HIGH |
| Initial Access | T1078.004 | Valid Accounts: Cloud | Reuse of IAB-purchased VPN credentials against healthcare M365 tenants. | HIGH |
| Execution | T1059.001 | Command and Scripting: PowerShell | Encoded loaders for SystemBC / Cobalt Strike in Qilin, INC Ransom, Akira tradecraft. | MEDIUM |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Microsoft Defender BlueHammer LPE against Windows clinical-workstation estates. | MEDIUM |
| Privilege Escalation | T1404 | Exploitation for Privilege Escalation (Android) | Android Framework CVE-2025-48595 - limited targeted exploitation per Google. | MEDIUM-HIGH |
| Credential Access | T1056 | Input Capture | Skimmer / keylogger implantation on patient-facing kiosks. | MEDIUM |
| Lateral Movement | T1021.001 | Remote Services: RDP | Pivot via RDP to ESXi and clinical-system infrastructure prior to encryption. | HIGH |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | rclone / MEGAcmd push to attacker cloud prior to encryption. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | ESXi-aware Qilin.B, INC Ransom and Akira encryptors against healthcare hypervisor estates. | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 02 Jun 2026 | Google Android - limited targeted exploitation | Unattributed | CVE-2025-48595 confirmed under limited targeted exploitation per Google; KEV addition 02 Jun. | Google / CISA |
| 02 Jun 2026 | Fortinet FortiClient EMS (vendor) | Unattributed | CVE-2026-35616 confirmed in-the-wild; healthcare-supplier exposure substantial. | watchTowr Labs |
| 02 Jun 2026 | Microsoft Defender platform (vendor) | Multiple | BlueHammer LPE chain disclosed; clinical-workstation EDR risk. | Microsoft / The Hacker News |
| Continuing | DXS International / Barts Health aftermath | Devman / multiple | UK NHS-supplier loss narrative continues; Barts Health legal action ongoing. | NHS England / Computing |
| Ongoing | Qilin / INC Ransom / SAFEPAY / Akira leak sites | Multiple | May 2026: healthcare in top three target sub-sectors by H-ISAC tracking. | Health-ISAC / BreachSense |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-35616 | Fortinet FortiClient EMS - pre-auth RCE; active in-the-wild exploitation reported by watchTowr 02 Jun 2026 | 9.8 | Yes | Yes | Patch to 7.4.2 or later; restrict EMS admin interface to management VLAN |
| CVE-2026-33825 | Microsoft Defender Antimalware Platform - BlueHammer LPE / defence-evasion (<4.18.26040.1011) | 8.4 | Yes | Yes | Force MoCAMP rollout; hunt for FortiGate SSL-VPN sessions terminating from RU/SG/CH |
| CVE-2026-45585 | Microsoft Windows BitLocker - YellowKey bypass; in-the-wild PoC live | 7.1 | Yes | Suspected | Apply June mitigation guidance; enforce TPM+PIN on regulated workstations |
| CVE-2026-42897 | Microsoft Exchange Server (SE / 2019 / 2016) - OWA crafted-email XSS (continuing exploitation) | 8.1 | Yes | Yes | Apply 14 May 2026 OOB update if not already; disable external OWA pending patch |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller / Manager - auth bypass; UAT-8616 continuing campaign | 10.0 | Yes | Yes | Verify Emergency Directive 26-03 closure; rotate SSH keys; review NETCONF logs |
| CVE-2026-6973 | Ivanti EPMM - admin credential reuse chain (post CVE-2026-1340) | 7.2 | Yes | Yes | Rotate any EPMM admin credential issued before 01 Feb 2026; confirm patch level |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer (Magento) - deserialisation; KEV 03 Jun 2026 | 9.8 | Yes | Yes | Patch immediately; isolate Magento admin behind WAF; hunt for unsigned PHP cache entries |
| CVE-2025-48595 | Android Framework - integer-overflow LPE; KEV 02 Jun 2026; limited/targeted exploitation observed by Google | 7.8 | Yes | Yes | Push June 2026 Android security patch to MDM-managed handsets |
| CVE-2022-0492 | Linux Kernel cgroup release_agent - KEV 02 Jun 2026 for revived container-escape campaigns | 7.8 | Yes | Yes | Validate kernels >=5.17; audit container hosts for unconfined cgroup mounts |
| CVE-2026-41091 | (KEV-listed; FCEB remediation due 03 Jun 2026) | - | Yes | Yes | Patch per CISA guidance |
| CVE-2026-45498 | (KEV-listed; FCEB remediation due 03 Jun 2026) | - | Yes | Yes | Patch per CISA guidance |
| CVE-2026-N8N-CRIT | n8n self-hosted - max-severity authentication-bypass per CyberScoop research (defenders rushing PoC) | 9.8 | Yes | Suspected | Upgrade to patched build; restrict n8n console to private network only |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 85[.]137[.]228[.]167 | 30 May 2026 | H | ServeTheWorld AS (NO); IP Insights threat_score 100, 8 blacklists incl. Emerging Threats Compromised, Brute Force Blocker, Malicious IP - SSH/brute-force cluster |
| IP | 79[.]143[.]178[.]79 | 31 May 2026 | H | contabo.DE; threat_score 100, 7 blacklists incl. ThreatFox malware family - staged loader infrastructure |
| IP | 176[.]65[.]139[.]151 | 01 Jun 2026 | H | Offshore LC (LU); threat_score 100, 7 blacklists - recurring bullet-proof hosting for brute-force |
| IP | 212[.]19[.]134[.]75 | 02 Jun 2026 | H | JSC Kazakhtelecom (KZ); threat_score 100, 8 blacklists; SSH/Telnet brute force at scale |
| IP | 27[.]79[.]41[.]68 | 03 Jun 2026 | H | Viettel Group (VN); threat_score 100, 7 blacklists; SSH brute force |
| IP | 103[.]77[.]246[.]158 | 04 Jun 2026 | H | Megacore Technology (VN); threat_score 100, 7 blacklists; sustained brute-force |
| IP | 34[.]86[.]81[.]254 | 31 May 2026 | M | Google LLC datacentre (US); IP Insights flagged 'critical'; abuse of cloud egress for compromised-stack traffic |
| IP | 136[.]117[.]199[.]185 | 02 Jun 2026 | M | Google LLC datacentre (US); IP Insights 'critical'; cloud-egress abuse |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment via VPN-credential IAB (Akira / Qilin / INC Ransom / SAFEPAY) | HIGH | HIGH | CRITICAL |
| Edge-appliance exploitation (Fortinet EMS / Cisco SD-WAN / Exchange OWA) | HIGH | HIGH | CRITICAL |
| Android-handset compromise via CVE-2025-48595 in MDM-managed clinical estate | MEDIUM-HIGH | HIGH | HIGH |
| EDR-control-plane compromise via Microsoft Defender BlueHammer chain | MEDIUM | HIGH | HIGH |
| Supply-chain compromise via NHS or private-healthcare supplier | HIGH | HIGH | CRITICAL |
| AI-enabled social engineering against contact-centres and clinical-staff verification | HIGH | MEDIUM | HIGH |
| BeyondTrust-pattern compromise of remote-access tooling | MEDIUM | HIGH | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Defend
Preventive priorities: patch Fortinet FortiClient EMS to 7.4.2 or later as the single highest-value action of the cycle; force the June 2026 Android security patch via MDM to all clinical and patient-facing handsets; force MoCAMP 4.18.26040.1011; apply the 14 May Exchange OOB update; verify SD-WAN ED 26-03 closure. Rotate any VPN admin credentials whose issue-date predates 01 February 2026. Strengthen caller-verification scripts at NHS-supplier and private-healthcare contact-centres to incorporate deepfake-resistant secondary-channel verification. Reference NHS DSP Toolkit and ISO/IEC 27001 Annex A.5.7, A.8.8 and A.5.23, and the H-ISAC standing supplier-resilience advisory.
Disrupt
Disruption priorities: (i) sustained Health-ISAC participation and Heartbeat indicator exchange, with this week's IP Insights 'critical' tail submitted as the highest-value contribution; (ii) coordinated takedown of attacker-controlled rclone / MEGA / AzCopy egress destinations through registrar-abuse and Cloudflare / Microsoft / Google trust-and-safety channels; (iii) tabletop exercises around the NHS-supplier supply-chain scenario and the deepfake caller-verification bypass; (iv) deception deployment around fake VPN endpoints and fake clinical-system admin endpoints.
10. Forward outlook
Looking forward to the next reporting period (06 - 12 June 2026), it is highly likely that at least one UK or EU healthcare-supplier entity will be named on a Qilin, INC Ransom, SAFEPAY or Akira leak-site posting, with HIGH confidence based on the May 2026 cadence and Health-ISAC tracking. It is likely that at least one publicly-disclosed Android-handset compromise traceable to CVE-2025-48595 will surface within the cycle. It is a realistic possibility that an AI-enabled social-engineering incident against a UK NHS-supplier contact-centre will be reported.
Trigger conditions that would prompt revision include: (a) a UK NHS-supplier publicly attributing a breach to Akira VPN-credential exploitation or FortiClient EMS; (b) a Health-ISAC TLP:CLEAR Heartbeat advisory pointing to a sector-wide campaign; (c) NCSC-UK or NHS England notice of supplier-chain compromise.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | CISA KEV Catalog updates 27 May, 02 Jun and 03 Jun 2026 - https://www.cisa.gov/known-exploited-vulnerabilities-catalog | CISA | A1 |
| 2 | CISA Alert - CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2022-0492, CVE-2025-48595), 02 Jun 2026 | CISA | A1 |
| 3 | CISA Alert - CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-45247), 03 Jun 2026 | CISA | A1 |
| 4 | NCSC-UK weekly threat report and advisory feed (week ending 05 Jun 2026) - https://www.ncsc.gov.uk/section/keep-up-to-date/threat-reports | NCSC | A1 |
| 5 | ESET APT Activity Report - October 2025 to March 2026 | ESET | B2 |
| 6 | Health-ISAC Heartbeat & 2026 Global Health Sector Threat Landscape Report | Health-ISAC | A2 |
| 7 | Check Point Research - Ransomware Quarterly Insights and May 2026 retrospective | Check Point Research | B2 |
| 8 | BreachSense - May 2026 Ransomware Report (646 victims, 61 groups) | BreachSense | C2 |
| 9 | Ransomware.live - leak-site tracker (Qilin / TheGentlemen / Akira / DragonForce postings, w/e 05 Jun 2026) | Ransomware.live | C2 |
| 10 | watchTowr Labs - Fortinet FortiClient EMS Zero-Day CVE-2026-35616, 02 Jun 2026 | watchTowr | B2 |
| 11 | The Hacker News - Microsoft mitigation for YellowKey BitLocker bypass CVE-2026-45585 | The Hacker News | B2 |
| 12 | The Hacker News - Microsoft warns of two actively exploited Defender vulnerabilities (BlueHammer) | Microsoft / The Hacker News | B1 |
| 13 | CyberScoop - researchers warn of max-severity defect in n8n self-hosted | CyberScoop | B2 |
| 14 | IP Insights - IP reputation enrichment (https://www.ipinsights.io) | UK Cyber Defence Ltd | B2 |
| 16 | Health-ISAC - Hospitals at Risk of BeyondTrust Ransomware Hacks (standing) | Health-ISAC | A2 |
| 17 | Health-ISAC - Feds, AHA Warn Health Sector of Evolving Akira Threat | Health-ISAC | A2 |
| 18 | NHS DSP Toolkit - supplier resilience standing requirements | NHS England | A1 |
| 19 | The Cyber Express - CVE-2025-48595 Fixed In Android June 2026 Security Update | The Cyber Express | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Healthcare Threat Intelligence Briefing
Healthcare Sector Ransomware Threat Analysis, May 2025
Healthcare threat intelligence report — 27 April – 3 May 2026
The healthcare threat picture for the reporting period continues to escalate. Health-ISAC reporting flags a 55% surge in cyber incidents in 2025 with continued escalation expected in 2026.
Healthcare threat intelligence report — 4–8 May 2026
The healthcare threat picture for the reporting period continues to escalate.