For MSSPs
Scale threat-led services across your customers
For Internal SOCs
Run threat-led operations in your own environment
Integrations
Connect Sol to your security stack
Blog
Latest articles and insights
About Us
Meet the people and purpose behind Elezar
Account
Login
Create Account
Support
Help Centre
Legal
Terms & Conditions
Privacy Policy
The Americas Healthcare and Hospitals sector had the strongest and most detailed intelligence coverage in the source set. Insomnia targeted US healthcare through encryptor-free data theft and WSUS abuse. Sinobi focused on mid-market health systems through SonicWall and MSP credentials. INC Ransomware expanded BYOVD EDR termination and Veeam credential theft, while the Code Blue assessment documented 233 million exposed records, 35 breaches and 37 weaponized CVEs across the broader healthcare landscape. Pediatric hospitals remained high-value targets because stolen child identity data can retain criminal value for more than a decade.
Recommendations are calibrated for clinical systems, EHR and PACS environments, hospital Active Directory, remote-access appliances, backup infrastructure, MSP dependencies and patient-safety continuity.
EMEA Healthcare and Hospitals faced a June threat environment shaped by ransomware-as-a-service, perimeter credential theft and social engineering. The Gentlemen emerged as the most operationally important ransomware group, with confirmed healthcare targeting, a documented healthcare case study, European infrastructure and domain-wide GPO deployment. FortiBleed confirmed dedicated European credential collection from FortiGate environments, while Microsoft Teams vishing campaigns directly targeted healthcare employees and executed Kerberoasting during live support impersonation sessions. Insomnia and pediatric-focused ransomware activity added further data-extortion and long-duration identity-theft risk.
APAC Healthcare and Hospitals faced a materially elevated threat environment in June 2026, but the supplied source set contained no APAC-specific healthcare incident report for the month. The principal intelligence source was HiveForce Labs' global healthcare analysis, which documented 35 disclosed breaches, 37 exploited CVEs and approximately 233 million exposed records from January 2025 through June 2026. Regional relevance is strongest where actor evidence is direct, particularly Lazarus Group's adoption of Medusa RaaS and the exposure of APAC hospitals to the same internet-facing appliance, credential-stealer and double-extortion attack paths. This section keeps confirmed reporting separate from regional inference.