May 2025 Healthcare Threat Intelligence Briefing
Healthcare Sector Ransomware Threat Analysis, May 2025
SOC status:Duty analyst on shift
Insights
Research, detection engineering notes and plain-English explanations for the questions UK boards, IT managers and security leads actually ask. One substantial piece a week; a short threat brief in between.
Get the fortnightly briefing
Healthcare Sector Ransomware Threat Analysis, May 2025
Government Sector Ransomware Threat Analysis – May 2025
Threat Analysis of Finance Sector Breaches for May 2025
Threat Analysis of the Energy Industry Sector – 1 May 2025 to 31 May 2025
Threat Analysis of the Education Sector (1 May 2025 – 31 May 2025)
Threat Analysis of the Defence Industry Sector – May 2025
Threat Analysis of the Banking Sector: 01/05/2025 to 31/05/2025
On May 20, 2025, Kettering Health, a major healthcare network based in Ohio, experienced a ransomware attack that severely disrupted its operations. As a result, all 14 hospitals in the system were placed on emergency reroute. This meant ambulances were redirected, and staff had to switch to manual processes because digital systems—including electronic health records, internal messaging, and coordination platforms—became unavailable.
An insights article assessing pro-Russian cyber activity with a situational briefing on hybrid threats to UK-aligned institutions. Includes a side-by-side comparison of key threat groups including KillNet, NoName057(16), and XakNet.
An insights article comparing donation-model ransomware operators such as MalasLocker, exploring the ethics, tactics, and implications of threat actors who demand charitable giving instead of cryptocurrency payments.
Western Alliance Bank confirmed a data breach in April 2025 caused by a flaw in Cleo software. Learn how it happened and what actions the bank is taking.
The DBS Data Breach 2025 involved a ransomware attack on a third-party vendor, exposing 11,000 customer records from DBS Bank and Bank of China Singapore.
216 articles · page 12 of 18