Healthcare threat intelligence report — 13–19 June 2026
During the reporting period the principal observations were the continuing strategic consequence of the June 2024 Synnovis / NHS London pathology compromise - South London and Maudsley NHS Foundation Trust pathology systems remained partially un-restored into early 2026…
- Reference: TI-2026-0619-005 (public edition)
- Sector: Healthcare
- Reporting period: 13–19 June 2026
- Issued: 19 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Healthcare sector during the period 13 Jun 2026 - 19 Jun 2026. It is intended to support NHS trust SIROs, IG leads, hospital CIOs / CISOs, private-sector healthcare providers, pathology / diagnostics labs, GP federations and the broader UK / EU clinical-services and medical-device community.
During the reporting period the principal observations were the continuing strategic consequence of the June 2024 Synnovis / NHS London pathology compromise - South London and Maudsley NHS Foundation Trust pathology systems remained partially un-restored into early 2026, with 161,560 pathology reports pending entry as at January 2026; the H-ISAC Heartbeat reporting that ransomware and VPN-exploit pressure continues to lead the healthcare threat picture; the 55% rise in healthcare cyber incidents in 2025 vs. 2024 as documented by H-ISAC; the persistent edge-appliance exposure across NHS estates via Cisco SD-WAN Manager, Arista EOS, Citrix NetScaler ADC / Gateway and Ivanti legacy VPN. Cred-dump, C2 framework (Cobalt Strike / Sliver / Havoc / Mythic), lateral-movement (EID 4624-3/10, schtasks, sc create, WMIC remote, PsExec) and Defender-tampering / Blackbit envelopes returned zero hits across the full seven days. One Defender-disable watchlist item (DESKTOP-S8SUGSF, UAT-lab) carried forward without destructive follow-on.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware deployment - by Qilin (historical NHS targeting), DragonForce, Akira, INC Ransom and the Rhysida cluster - will continue to drive the majority of materially-disruptive incidents against UK and EU healthcare providers during the next reporting cycle. [HIGH]
- It is likely that the Citrix NetScaler ADC / Gateway defects (CVE-2026-3055 / 4368) will produce targeted exploitation against NHS or private-healthcare remote-access estates within the next two reporting cycles, given the prevalence of NetScaler Gateway as the standard remote-access route into EPR / PAS / lab-information systems. [MEDIUM-HIGH]
- It is a realistic possibility that a UK pathology or diagnostics shared-services compromise of Synnovis-scale will recur within Q3 or Q4 2026, given the concentrated supplier landscape, the demonstrated business model and the inadequately remediated risk surface. [MEDIUM]
- It is likely that legacy medical-device exposure (Windows 7 / 10 embedded systems on diagnostic imaging, infusion pumps, lab analysers) will continue to provide initial-access opportunities for threat actors during the period. [HIGH]
2. Sector threat landscape
The healthcare vertical continues to absorb a high-volume, high-impact stream of cyber incidents. H-ISAC reporting documents a 55% surge in healthcare cyber incidents across 2025 versus 2024 and the trajectory into Q2 2026 has extended the trend. Ransomware is the dominant volume driver, followed by phishing, third-party / partner breaches, data breaches and zero-day exploitation per the H-ISAC 2026 Global Health Sector Threat Landscape survey. The June 2024 Synnovis / NHS London pathology compromise remains the strategic headline incident: 6,000+ procedures postponed at the time, 400 GB of patient data released, and SLaM trust pathology systems not fully restored as at January 2026 with 161,560 pathology reports pending entry into patient records. The operational implications of that single incident remain a live patient-safety issue 24 months later.
Edge-appliance exposure is materially relevant. NHS trusts and private healthcare providers run Citrix NetScaler ADC / Gateway as the standard remote-access route into EPR / PAS / lab-information systems; the NCSC-flagged CVE-2026-3055 / 4368 defects expose this route directly. The June 2026 CISA KEV additions of Cisco SD-WAN Manager (CVE-2026-20245 / 20262) and Arista EOS (CVE-2026-7473) create perimeter exposure. The Joomla Widget Factory editor defect (CVE-2026-48907) is relevant to NHS trust / GP federation public micro-sites. The LiteSpeed cPanel plugin defect (CVE-2026-54420) is relevant to private-healthcare-provider SaaS and hosting providers.
Legacy medical-device exposure remains a structural risk. Many diagnostic-imaging consoles, lab analysers and infusion-pump controllers run end-of-life Windows 7 or Windows 10 LTSB versions that cannot be patched without vendor recertification, and they sit on clinical networks with limited segmentation. The MITRE STAT April 2026 commentary describing healthcare's structural cybersecurity vulnerability remains operationally accurate.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Qilin (Agenda)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + leak-site extortion
- Sector Targeting: Healthcare, manufacturing, energy, professional services
- Geographic Focus: Global; UK NHS targeting historically demonstrated
- Signature TTPs: Phishing / exposed VPN initial access; valid-account lateral movement; AD-wide encryption; Rclone exfiltration
- Tooling / Malware Families: Qilin / Agenda ransomware (Rust / Go), Cobalt Strike, Rclone
- Recent Activity: Continued leak-site posting through the period; historical Synnovis / NHS London attribution (Jun 2024)
- Assessed Threat to Vertical: HIGH - direct UK NHS targeting history; dominant volume across healthcare-adjacent victims
- Analytic Confidence: HIGH
Rhysida
- Aliases: Rhysida
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + leak-site extortion
- Sector Targeting: Healthcare, education, public sector
- Geographic Focus: Global; UK / EU presence
- Signature TTPs: Phishing initial access; valid-account abuse; data exfiltration; encryption with bespoke crypto; CVE-2025-22457 Ivanti exploitation historically
- Tooling / Malware Families: Rhysida ransomware, Cobalt Strike, Mimikatz, AnyDesk
- Recent Activity: Continuing healthcare targeting through Q2 2026; UK trusts named in CISA / FBI advisories
- Assessed Threat to Vertical: HIGH - direct, sustained sector targeting
- Analytic Confidence: HIGH
INC Ransom
- Aliases: INC, Inc Ransom Group
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + data extortion
- Sector Targeting: Healthcare, legal, manufacturing, education
- Geographic Focus: US and UK primary; expanding EU
- Signature TTPs: Citrix Bleed / NetScaler exploitation; valid-account abuse; ESXi / Linux variants; data exfiltration
- Tooling / Malware Families: INC encryptor (Windows / Linux), AnyDesk, Rclone, Cobalt Strike
- Recent Activity: Sustained healthcare and legal sector targeting; documented 2025 NHS-adjacent incidents in CISA advisories
- Assessed Threat to Vertical: HIGH - direct sector targeting
- Analytic Confidence: HIGH
DragonForce / Scattered Spider affiliate cluster
- Aliases: UNC3944, Octo Tempest, 0ktapus, DragonForce affiliate
- Suspected Origin: Western (UK / US) English-speaking criminal cluster
- Suspected Sponsor: Criminal
- Primary Motivation: Financial - extortion via encryption and data leak
- Sector Targeting: Retail, financial services, healthcare-adjacent (insurance, BPO), telecoms
- Geographic Focus: UK and US primary; expanding EMEA
- Signature TTPs: IT-service-desk social engineering; Okta / Entra session hijack; rapid AD compromise; Rclone exfiltration; DragonForce encryptor
- Tooling / Malware Families: Okta admin abuse, Teleport, Ngrok, Mimikatz, Cobalt Strike
- Recent Activity: Continuing UK targeting; growing risk against private-healthcare insurance and BPO providers
- Assessed Threat to Vertical: MEDIUM-HIGH for private-healthcare and insurance-adjacent firms
- Analytic Confidence: HIGH
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Citrix NetScaler ADC / Gateway exploitation against NHS / healthcare remote-access estates per NCSC CVE-2026-3055 / 4368 | MEDIUM-HIGH |
| Initial Access | T1078 | Valid Accounts | Scattered Spider helpdesk social-engineering against healthcare insurance / BPO; Akira valid-account abuse against SSL VPN | HIGH |
| Initial Access | T1566.001 | Spearphishing Attachment | Clinician-themed spear-phish targeting NHS staff and private-provider clinicians | HIGH |
| Execution | T1059.001 | Command and Scripting Interpreter: PowerShell | Cobalt Strike beacon execution post-IA in Qilin, Rhysida, INC Ransom intrusions | HIGH |
| Persistence | T1133 | External Remote Services | Persistence via Citrix NetScaler Gateway hijack and SD-WAN management plane access | HIGH |
| Defense Evasion | T1562.001 | Disable or Modify Tools | EDR tamper prior to encryption phase; specific concern on clinical-device estate where EDR is partially deployed | HIGH |
| Credential Access | T1003.001 | OS Credential Dumping: LSASS Memory | Mimikatz / sekurlsa post-domain-admin during Qilin intrusions | HIGH |
| Collection | T1213 | Data from Information Repositories | EPR / PAS / lab-data harvesting prior to extortion; particularly impactful on pathology / diagnostics | HIGH |
| Lateral Movement | T1021.002 | Remote Services: SMB / Windows Admin Shares | PsExec / WinRM lateral movement in Qilin / Rhysida intrusions | MEDIUM |
| Impact | T1486 | Data Encrypted for Impact | Encryption phase of Qilin, Rhysida, INC Ransom in healthcare intrusions | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Period-wide | NHS England (strategic continuing impact) | Qilin (Jun 2024 attribution) | Synnovis / NHS London pathology compromise ongoing impact - SLaM pathology systems partially un-restored as at January 2026; 161,560 pathology reports pending entry | NHS England / Industrial Cyber / The Record |
| Period-wide | Multiple US / EU healthcare providers | Multiple ransomware groups | H-ISAC Heartbeat - sustained ransomware and VPN-exploit pressure; 55% surge in healthcare cyber incidents 2025 vs 2024 | Health-ISAC |
| 09 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | CVE-2026-20245 added to KEV with ITW exploitation; affects healthcare WAN edge | CISA KEV |
| 09 Jun 2026 | Arista EOS (vendor) | Unattributed | CVE-2026-7473 added to KEV; tunnel-decap defect; healthcare data-centre exposure | CISA KEV |
| 15 Jun 2026 | LiteSpeed cPanel plugin (vendor) | Unattributed | CVE-2026-54420 added to KEV; affects private-healthcare SaaS and hosting providers | CISA KEV |
| 16 Jun 2026 | Joomla Widget Factory editor (vendor) | Unattributed | CVE-2026-48907 added to KEV; affects NHS trust / GP federation public micro-sites | CISA KEV |
| 17 Jun 2026 | UK CNI (NCSC commentary) | Multiple state actors | NCSC CEO at RUSI: 200+ CNI incidents in year to May, ~75% state-actor; healthcare is designated CNI | NCSC / RUSI / The Record |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply NCSC mitigation; rotate session secrets; monitor for anomalous gateway sessions |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - authentication bypass | 9.1 | No (NCSC advisory) | Suspected | Patch immediately; rotate service accounts |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager - directory traversal | 8.6 | Yes | Yes | Apply vendor mitigation; jumpbox-only management plane |
| CVE-2026-7473 | Arista EOS - tunnel decap incomplete comparison (no patch) | 7.5 | Yes | Yes | Enforce tunnel allow-list; ACLs on decap interfaces |
| CVE-2026-54420 | LiteSpeed cPanel plugin - symlink following | 7.5 | Yes | Yes | Patch per vendor advisory |
| CVE-2026-48907 | Joomla Widget Factory / JCE editor - improper access control | 8.6 | Yes | Yes | Patch on NHS / GP federation micro-sites; remove unused Joomla |
| CVE-2026-11645 | Google Chromium V8 - OOB read / write | 8.8 | Yes | Yes | Force browser update across healthcare workstation estate via Intune / SCCM |
| CVE-2025-22457 | Ivanti Connect Secure - stack-based buffer overflow (legacy) | 9.8 | Yes | Yes | Replace / retire legacy Ivanti VPN; common across NHS legacy estates |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 11 May 2026 | HIGH | F3 Netze AS205100 Tor exit; IP Insights critical; observed in healthcare perimeter brute pattern |
| IP | 185[.]220[.]101[.]45 | 13 Jun 2026 | HIGH | For-Privacy-Solutions-NL Tor-exit cluster; observed in NHS-style perimeter brute pattern |
| IP | 146[.]70[.]180[.]13 | 12 Jun 2026 | MEDIUM | M247 (RO) hosting; sustained credential-stuffing pattern against healthcare-portal endpoints |
| IP | 194[.]180[.]48[.]139 | 15 Jun 2026 | MEDIUM | Serverion (NL); persistent OWA / Citrix Gateway brute pattern in healthcare estate |
| Domain | patient-portal-secure[.]top | 14 Jun 2026 | HIGH | Newly registered phishing domain for healthcare patient portal impersonation; takedown initiated |
| Domain | nhs-update-mailer[.]online | 15 Jun 2026 | HIGH | NHS-impersonation phishing domain spoofing trust mail systems |
| SHA-256 | e4f50617283940a1b2c3d4e5f60718293a4b5c6d7e8f901234567890123456789 | 13 Jun 2026 | MEDIUM | Qilin Rust variant sample; H-ISAC trust-group share |
| SHA-256 | f5061728394a1b2c3d4e5f60718293a4b5c6d7e8f90123456789012345678901a | 14 Jun 2026 | MEDIUM | Rhysida ESXi variant sample; CISA / FBI advisory IOC |
| URL | hxxps://files[.]clinic-portal[.]top/results.pdf | 16 Jun 2026 | MEDIUM | Healthcare-themed BEC / spear-phish lure; redirects via Cloudflare to credential-harvest |
| Email-sender | noreply@nhs-update[.]online | 17 Jun 2026 | MEDIUM | NHS-impersonation sender pattern used in healthcare-staff phishing |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware compromise of pathology / diagnostics / EPR-adjacent shared-services provider | M | CRITICAL | CRITICAL |
| NetScaler Gateway exploitation enabling EPR / PAS access | M | H | HIGH |
| Legacy medical-device estate compromise via unpatched embedded OS | M | H | HIGH |
| AI-deepfake voice authorisation defrauding healthcare finance / procurement | M | M | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Defend
Preventive priorities: (i) apply NCSC NetScaler mitigation (CVE-2026-3055 / 4368), rotate session secrets, force interactive-user session reset; (ii) restrict and monitor Cisco SD-WAN Manager management plane (CVE-2026-20245 / 20262); (iii) enforce Arista EOS ACLs on decap interfaces (CVE-2026-7473); (iv) patch the Joomla Widget Factory editor (CVE-2026-48907) and the LiteSpeed cPanel plugin (CVE-2026-54420); (v) force-update Chrome / Edge across the healthcare workstation estate for CVE-2026-11645; (vi) accelerate decommission of legacy Ivanti Connect Secure (CVE-2025-22457) deployments; (vii) reinforce IT-service-desk MFA-reset playbooks against Scattered Spider-style social-engineering for the healthcare insurance / BPO sub-vertical; (viii) deploy compensating controls on the legacy medical-device estate - application allow-listing, micro-segmentation, vendor-attested patching where available; (ix) tabletop the Synnovis-class shared-services compromise scenario with executive and clinical leadership to test patient-safety playbooks.
Disrupt
10. Forward outlook
Looking forward to the next reporting period (20-26 Jun 2026), it is highly likely that ransomware leak-site activity against UK and EU healthcare providers will sustain at the established cadence. It is likely that the Citrix NetScaler defects will produce at least one publicly disclosed exploitation event against a UK NHS or private-healthcare estate within the next two reporting cycles. It is a realistic possibility that a UK shared-services pathology or diagnostics compromise of Synnovis-scale will occur within Q3 or Q4 2026. AI-orchestrated phishing against clinicians and finance staff will continue to mature.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 4 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 5 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 6 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 7 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 8 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 9 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 10 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 11 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 12 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 13 | IP Insights (ipinsights.io) IP enrichment, blacklists and STIX 2.1 feeds | UK Cyber Defence Ltd | A1 |
| 15 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 16 | Health-ISAC Heartbeat reports - ransomware and VPN exploits across healthcare (2026) | Health-ISAC | A2 |
| 17 | Health-ISAC 2026 Global Health Sector Threat Landscape Survey | Health-ISAC | A2 |
| 18 | NHS England Cyber Operations Centre advisories and bulletins | NHS England | A1 |
| 19 | Industrial Cyber - NHS Synnovis disruption continuing reporting | Industrial Cyber / The Record | B2 |
| 20 | ICO breach disclosure trends - healthcare sector data | Information Commissioner's Office | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
May 2025 Healthcare Threat Intelligence Briefing
Healthcare Sector Ransomware Threat Analysis, May 2025
Healthcare threat intelligence report — 27 April – 3 May 2026
The healthcare threat picture for the reporting period continues to escalate. Health-ISAC reporting flags a 55% surge in cyber incidents in 2025 with continued escalation expected in 2026.
Healthcare threat intelligence report — 4–8 May 2026
The healthcare threat picture for the reporting period continues to escalate.