INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Cybercriminals Target Healthcare Businesses
| 2026-07-10 16:51 DATA BREACH
Executive Summary
AI-generated
In the first half of 2026, cyberattacks on healthcare businesses surged by 35% compared to the second half of 2025 and 110% compared to the same six months from the previous year. This significant increase is attributed to attackers recognizing that compromising a single provider can provide access to multiple hospitals, as Rebecca Moody, head of data research at Comparitech, notes. The US healthcare industry has been targeted by ransomware groups such as Qilin, while newer groups like The Gentlemen appear to be focusing on Europe and other regions. Cybercriminals are flocking to healthcare businesses due to the potential for accessing multiple hospitals through a single central hub, putting pressure on affected entities to answer to their clients and increasing the chances of getting their ransom.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Impersonation): Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in-
• Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation.
• Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Intelligence Sources
Dark Reading
2026-07-10