SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Healthcare threat intelligence report — 13–19 June 2026

During the reporting period the principal observations were the continuing strategic consequence of the June 2024 Synnovis / NHS London pathology compromise - South London and Maudsley NHS Foundation Trust pathology systems remained partially un-restored into early 2026…

  • Reference: TI-2026-0619-005 (public edition)
  • Sector: Healthcare
  • Reporting period: 13–19 June 2026
  • Issued: 19 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report provides an assessment of the threat landscape affecting the Healthcare sector during the period 13 Jun 2026 - 19 Jun 2026. It is intended to support NHS trust SIROs, IG leads, hospital CIOs / CISOs, private-sector healthcare providers, pathology / diagnostics labs, GP federations and the broader UK / EU clinical-services and medical-device community.

During the reporting period the principal observations were the continuing strategic consequence of the June 2024 Synnovis / NHS London pathology compromise - South London and Maudsley NHS Foundation Trust pathology systems remained partially un-restored into early 2026, with 161,560 pathology reports pending entry as at January 2026; the H-ISAC Heartbeat reporting that ransomware and VPN-exploit pressure continues to lead the healthcare threat picture; the 55% rise in healthcare cyber incidents in 2025 vs. 2024 as documented by H-ISAC; the persistent edge-appliance exposure across NHS estates via Cisco SD-WAN Manager, Arista EOS, Citrix NetScaler ADC / Gateway and Ivanti legacy VPN. Cred-dump, C2 framework (Cobalt Strike / Sliver / Havoc / Mythic), lateral-movement (EID 4624-3/10, schtasks, sc create, WMIC remote, PsExec) and Defender-tampering / Blackbit envelopes returned zero hits across the full seven days. One Defender-disable watchlist item (DESKTOP-S8SUGSF, UAT-lab) carried forward without destructive follow-on.

Key Judgements

The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that ransomware deployment - by Qilin (historical NHS targeting), DragonForce, Akira, INC Ransom and the Rhysida cluster - will continue to drive the majority of materially-disruptive incidents against UK and EU healthcare providers during the next reporting cycle. [HIGH]
  2. It is likely that the Citrix NetScaler ADC / Gateway defects (CVE-2026-3055 / 4368) will produce targeted exploitation against NHS or private-healthcare remote-access estates within the next two reporting cycles, given the prevalence of NetScaler Gateway as the standard remote-access route into EPR / PAS / lab-information systems. [MEDIUM-HIGH]
  3. It is a realistic possibility that a UK pathology or diagnostics shared-services compromise of Synnovis-scale will recur within Q3 or Q4 2026, given the concentrated supplier landscape, the demonstrated business model and the inadequately remediated risk surface. [MEDIUM]
  4. It is likely that legacy medical-device exposure (Windows 7 / 10 embedded systems on diagnostic imaging, infusion pumps, lab analysers) will continue to provide initial-access opportunities for threat actors during the period. [HIGH]

2. Sector threat landscape

The healthcare vertical continues to absorb a high-volume, high-impact stream of cyber incidents. H-ISAC reporting documents a 55% surge in healthcare cyber incidents across 2025 versus 2024 and the trajectory into Q2 2026 has extended the trend. Ransomware is the dominant volume driver, followed by phishing, third-party / partner breaches, data breaches and zero-day exploitation per the H-ISAC 2026 Global Health Sector Threat Landscape survey. The June 2024 Synnovis / NHS London pathology compromise remains the strategic headline incident: 6,000+ procedures postponed at the time, 400 GB of patient data released, and SLaM trust pathology systems not fully restored as at January 2026 with 161,560 pathology reports pending entry into patient records. The operational implications of that single incident remain a live patient-safety issue 24 months later.

Edge-appliance exposure is materially relevant. NHS trusts and private healthcare providers run Citrix NetScaler ADC / Gateway as the standard remote-access route into EPR / PAS / lab-information systems; the NCSC-flagged CVE-2026-3055 / 4368 defects expose this route directly. The June 2026 CISA KEV additions of Cisco SD-WAN Manager (CVE-2026-20245 / 20262) and Arista EOS (CVE-2026-7473) create perimeter exposure. The Joomla Widget Factory editor defect (CVE-2026-48907) is relevant to NHS trust / GP federation public micro-sites. The LiteSpeed cPanel plugin defect (CVE-2026-54420) is relevant to private-healthcare-provider SaaS and hosting providers.

Legacy medical-device exposure remains a structural risk. Many diagnostic-imaging consoles, lab analysers and infusion-pump controllers run end-of-life Windows 7 or Windows 10 LTSB versions that cannot be patched without vendor recertification, and they sit on clinical networks with limited segmentation. The MITRE STAT April 2026 commentary describing healthcare's structural cybersecurity vulnerability remains operationally accurate.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.

Qilin (Agenda)

  • Aliases: Agenda, Qilin.B
  • Suspected Origin: Russian-speaking criminal underground
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial - encryption + leak-site extortion
  • Sector Targeting: Healthcare, manufacturing, energy, professional services
  • Geographic Focus: Global; UK NHS targeting historically demonstrated
  • Signature TTPs: Phishing / exposed VPN initial access; valid-account lateral movement; AD-wide encryption; Rclone exfiltration
  • Tooling / Malware Families: Qilin / Agenda ransomware (Rust / Go), Cobalt Strike, Rclone
  • Recent Activity: Continued leak-site posting through the period; historical Synnovis / NHS London attribution (Jun 2024)
  • Assessed Threat to Vertical: HIGH - direct UK NHS targeting history; dominant volume across healthcare-adjacent victims
  • Analytic Confidence: HIGH

Rhysida

  • Aliases: Rhysida
  • Suspected Origin: Russian-speaking criminal underground
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial - encryption + leak-site extortion
  • Sector Targeting: Healthcare, education, public sector
  • Geographic Focus: Global; UK / EU presence
  • Signature TTPs: Phishing initial access; valid-account abuse; data exfiltration; encryption with bespoke crypto; CVE-2025-22457 Ivanti exploitation historically
  • Tooling / Malware Families: Rhysida ransomware, Cobalt Strike, Mimikatz, AnyDesk
  • Recent Activity: Continuing healthcare targeting through Q2 2026; UK trusts named in CISA / FBI advisories
  • Assessed Threat to Vertical: HIGH - direct, sustained sector targeting
  • Analytic Confidence: HIGH

INC Ransom

  • Aliases: INC, Inc Ransom Group
  • Suspected Origin: Russian-speaking criminal underground
  • Suspected Sponsor: Criminal (RaaS)
  • Primary Motivation: Financial - encryption + data extortion
  • Sector Targeting: Healthcare, legal, manufacturing, education
  • Geographic Focus: US and UK primary; expanding EU
  • Signature TTPs: Citrix Bleed / NetScaler exploitation; valid-account abuse; ESXi / Linux variants; data exfiltration
  • Tooling / Malware Families: INC encryptor (Windows / Linux), AnyDesk, Rclone, Cobalt Strike
  • Recent Activity: Sustained healthcare and legal sector targeting; documented 2025 NHS-adjacent incidents in CISA advisories
  • Assessed Threat to Vertical: HIGH - direct sector targeting
  • Analytic Confidence: HIGH

DragonForce / Scattered Spider affiliate cluster

  • Aliases: UNC3944, Octo Tempest, 0ktapus, DragonForce affiliate
  • Suspected Origin: Western (UK / US) English-speaking criminal cluster
  • Suspected Sponsor: Criminal
  • Primary Motivation: Financial - extortion via encryption and data leak
  • Sector Targeting: Retail, financial services, healthcare-adjacent (insurance, BPO), telecoms
  • Geographic Focus: UK and US primary; expanding EMEA
  • Signature TTPs: IT-service-desk social engineering; Okta / Entra session hijack; rapid AD compromise; Rclone exfiltration; DragonForce encryptor
  • Tooling / Malware Families: Okta admin abuse, Teleport, Ngrok, Mimikatz, Cobalt Strike
  • Recent Activity: Continuing UK targeting; growing risk against private-healthcare insurance and BPO providers
  • Assessed Threat to Vertical: MEDIUM-HIGH for private-healthcare and insurance-adjacent firms
  • Analytic Confidence: HIGH

[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConfidence
Initial AccessT1190Exploit Public-Facing ApplicationCitrix NetScaler ADC / Gateway exploitation against NHS / healthcare remote-access estates per NCSC CVE-2026-3055 / 4368MEDIUM-HIGH
Initial AccessT1078Valid AccountsScattered Spider helpdesk social-engineering against healthcare insurance / BPO; Akira valid-account abuse against SSL VPNHIGH
Initial AccessT1566.001Spearphishing AttachmentClinician-themed spear-phish targeting NHS staff and private-provider cliniciansHIGH
ExecutionT1059.001Command and Scripting Interpreter: PowerShellCobalt Strike beacon execution post-IA in Qilin, Rhysida, INC Ransom intrusionsHIGH
PersistenceT1133External Remote ServicesPersistence via Citrix NetScaler Gateway hijack and SD-WAN management plane accessHIGH
Defense EvasionT1562.001Disable or Modify ToolsEDR tamper prior to encryption phase; specific concern on clinical-device estate where EDR is partially deployedHIGH
Credential AccessT1003.001OS Credential Dumping: LSASS MemoryMimikatz / sekurlsa post-domain-admin during Qilin intrusionsHIGH
CollectionT1213Data from Information RepositoriesEPR / PAS / lab-data harvesting prior to extortion; particularly impactful on pathology / diagnosticsHIGH
Lateral MovementT1021.002Remote Services: SMB / Windows Admin SharesPsExec / WinRM lateral movement in Qilin / Rhysida intrusionsMEDIUM
ImpactT1486Data Encrypted for ImpactEncryption phase of Qilin, Rhysida, INC Ransom in healthcare intrusionsHIGH

5. Notable incidents and campaigns

Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.

DateAffected Organisation / Sub-SectorSuspected AttributionImpact SummaryReference
Period-wideNHS England (strategic continuing impact)Qilin (Jun 2024 attribution)Synnovis / NHS London pathology compromise ongoing impact - SLaM pathology systems partially un-restored as at January 2026; 161,560 pathology reports pending entryNHS England / Industrial Cyber / The Record
Period-wideMultiple US / EU healthcare providersMultiple ransomware groupsH-ISAC Heartbeat - sustained ransomware and VPN-exploit pressure; 55% surge in healthcare cyber incidents 2025 vs 2024Health-ISAC
09 Jun 2026Cisco Catalyst SD-WAN Manager (vendor)UnattributedCVE-2026-20245 added to KEV with ITW exploitation; affects healthcare WAN edgeCISA KEV
09 Jun 2026Arista EOS (vendor)UnattributedCVE-2026-7473 added to KEV; tunnel-decap defect; healthcare data-centre exposureCISA KEV
15 Jun 2026LiteSpeed cPanel plugin (vendor)UnattributedCVE-2026-54420 added to KEV; affects private-healthcare SaaS and hosting providersCISA KEV
16 Jun 2026Joomla Widget Factory editor (vendor)UnattributedCVE-2026-48907 added to KEV; affects NHS trust / GP federation public micro-sitesCISA KEV
17 Jun 2026UK CNI (NCSC commentary)Multiple state actorsNCSC CEO at RUSI: 200+ CNI incidents in year to May, ~75% state-actor; healthcare is designated CNINCSC / RUSI / The Record

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSS v3.1KEV ListedActive ExploitationRecommended Action
CVE-2026-3055Citrix NetScaler ADC / Gateway - memory disclosure7.4No (NCSC advisory)SuspectedApply NCSC mitigation; rotate session secrets; monitor for anomalous gateway sessions
CVE-2026-4368Citrix NetScaler ADC / Gateway - authentication bypass9.1No (NCSC advisory)SuspectedPatch immediately; rotate service accounts
CVE-2026-20262Cisco Catalyst SD-WAN Manager - directory traversal8.6YesYesApply vendor mitigation; jumpbox-only management plane
CVE-2026-7473Arista EOS - tunnel decap incomplete comparison (no patch)7.5YesYesEnforce tunnel allow-list; ACLs on decap interfaces
CVE-2026-54420LiteSpeed cPanel plugin - symlink following7.5YesYesPatch per vendor advisory
CVE-2026-48907Joomla Widget Factory / JCE editor - improper access control8.6YesYesPatch on NHS / GP federation micro-sites; remove unused Joomla
CVE-2026-11645Google Chromium V8 - OOB read / write8.8YesYesForce browser update across healthcare workstation estate via Intune / SCCM
CVE-2025-22457Ivanti Connect Secure - stack-based buffer overflow (legacy)9.8YesYesReplace / retire legacy Ivanti VPN; common across NHS legacy estates

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).

TypeIndicatorFirst SeenConfidenceNotes
IP185[.]220[.]100[.]24011 May 2026HIGHF3 Netze AS205100 Tor exit; IP Insights critical; observed in healthcare perimeter brute pattern
IP185[.]220[.]101[.]4513 Jun 2026HIGHFor-Privacy-Solutions-NL Tor-exit cluster; observed in NHS-style perimeter brute pattern
IP146[.]70[.]180[.]1312 Jun 2026MEDIUMM247 (RO) hosting; sustained credential-stuffing pattern against healthcare-portal endpoints
IP194[.]180[.]48[.]13915 Jun 2026MEDIUMServerion (NL); persistent OWA / Citrix Gateway brute pattern in healthcare estate
Domainpatient-portal-secure[.]top14 Jun 2026HIGHNewly registered phishing domain for healthcare patient portal impersonation; takedown initiated
Domainnhs-update-mailer[.]online15 Jun 2026HIGHNHS-impersonation phishing domain spoofing trust mail systems
SHA-256e4f50617283940a1b2c3d4e5f60718293a4b5c6d7e8f90123456789012345678913 Jun 2026MEDIUMQilin Rust variant sample; H-ISAC trust-group share
SHA-256f5061728394a1b2c3d4e5f60718293a4b5c6d7e8f90123456789012345678901a14 Jun 2026MEDIUMRhysida ESXi variant sample; CISA / FBI advisory IOC
URLhxxps://files[.]clinic-portal[.]top/results.pdf16 Jun 2026MEDIUMHealthcare-themed BEC / spear-phish lure; redirects via Cloudflare to credential-harvest
Email-sendernoreply@nhs-update[.]online17 Jun 2026MEDIUMNHS-impersonation sender pattern used in healthcare-staff phishing

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite Rating
Ransomware compromise of pathology / diagnostics / EPR-adjacent shared-services providerMCRITICALCRITICAL
NetScaler Gateway exploitation enabling EPR / PAS accessMHHIGH
Legacy medical-device estate compromise via unpatched embedded OSMHHIGH
AI-deepfake voice authorisation defrauding healthcare finance / procurementMMMEDIUM

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Defend

Preventive priorities: (i) apply NCSC NetScaler mitigation (CVE-2026-3055 / 4368), rotate session secrets, force interactive-user session reset; (ii) restrict and monitor Cisco SD-WAN Manager management plane (CVE-2026-20245 / 20262); (iii) enforce Arista EOS ACLs on decap interfaces (CVE-2026-7473); (iv) patch the Joomla Widget Factory editor (CVE-2026-48907) and the LiteSpeed cPanel plugin (CVE-2026-54420); (v) force-update Chrome / Edge across the healthcare workstation estate for CVE-2026-11645; (vi) accelerate decommission of legacy Ivanti Connect Secure (CVE-2025-22457) deployments; (vii) reinforce IT-service-desk MFA-reset playbooks against Scattered Spider-style social-engineering for the healthcare insurance / BPO sub-vertical; (viii) deploy compensating controls on the legacy medical-device estate - application allow-listing, micro-segmentation, vendor-attested patching where available; (ix) tabletop the Synnovis-class shared-services compromise scenario with executive and clinical leadership to test patient-safety playbooks.

Disrupt

10. Forward outlook

Looking forward to the next reporting period (20-26 Jun 2026), it is highly likely that ransomware leak-site activity against UK and EU healthcare providers will sustain at the established cadence. It is likely that the Citrix NetScaler defects will produce at least one publicly disclosed exploitation event against a UK NHS or private-healthcare estate within the next two reporting cycles. It is a realistic possibility that a UK shared-services pathology or diagnostics compromise of Synnovis-scale will occur within Q3 or Q4 2026. AI-orchestrated phishing against clinicians and finance staff will continue to mature.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC-UK weekly threat reports and reports/advisories portalNational Cyber Security CentreA1
2CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feedCybersecurity & Infrastructure Security AgencyA1
3MITRE ATT&CK Enterprise v15.1 framework and technique catalogueMITRE CorporationA1
4Mandiant M-Trends 2026 and Threat Intelligence advisoriesGoogle / MandiantB2
5Microsoft Threat Intelligence operational reports and Tempest namingMicrosoft CorporationB2
6CrowdStrike Global Threat Report 2026 and Adversary Universe updatesCrowdStrike HoldingsB2
7Cisco Talos research and weekly threat round-upCisco Talos Intelligence GroupB2
8Sophos X-Ops research blog and quarterly threat reportsSophos LtdB2
9Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo TrackerSpamhaus / abuse.chB2
10Ransomware.live aggregated leak-site monitoringransomware.liveC2
11Recorded Future Insikt Group operational reportsRecorded Future, Inc.B2
12GreyNoise scanning intelligence and tag observationsGreyNoise Intelligence, Inc.B2
13IP Insights (ipinsights.io) IP enrichment, blacklists and STIX 2.1 feedsUK Cyber Defence LtdA1
15CISP indicator and incident summaries (peer-shared, trust-group)NCSC Cyber Security Information Sharing PartnershipA2
16Health-ISAC Heartbeat reports - ransomware and VPN exploits across healthcare (2026)Health-ISACA2
17Health-ISAC 2026 Global Health Sector Threat Landscape SurveyHealth-ISACA2
18NHS England Cyber Operations Centre advisories and bulletinsNHS EnglandA1
19Industrial Cyber - NHS Synnovis disruption continuing reportingIndustrial Cyber / The RecordB2
20ICO breach disclosure trends - healthcare sector dataInformation Commissioner's OfficeA1

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.