Skip to content
Flash Briefing high Healthcare

NHS Trusts Targeted in Coordinated Ransomware Wave as RaaS Affiliates Shift Focus

Three NHS trusts hit in six weeks. In one case, emergency ambulances were diverted. Patient administration systems down, elective procedures delayed, and a set of affiliates who have clearly decided that healthcare is a reliable payday working methodically through the sector.

The group behind these incidents is assessed as RansomHub affiliates, several of them previously linked to ALPHV/BlackCat before that operation collapsed in early 2024. Different banner, same playbook.

The entry point is embarrassingly predictable

All three intrusions came through the same class of vulnerability: unpatched remote access infrastructure. Legacy SSL VPN appliances and Citrix NetScaler gateways that hadn’t seen a security update in six months or more.

This is not sophisticated. The exploits are well-documented. The affected products (Ivanti Connect Secure, Cisco ASA, Citrix NetScaler) have had critical patches circulating for months. The sophistication isn’t in the initial access; it’s in what comes after. Rapid lateral movement through clinical networks, deliberate targeting of backup systems before encryption kicks in, and patient data exfiltrated first to anchor the double-extortion demand.

Any healthcare organisation still carrying outstanding patches on these products needs to treat that as this week’s problem, not next quarter’s.

Why healthcare keeps getting hit

The answer isn’t that health sector security teams are incompetent. It’s that the structural conditions are uniquely favourable to attackers.

Hospitals operate on margins that don’t accommodate extended downtime. A manufacturing plant can absorb a 48-hour outage and catch up. A hospital running at capacity with ambulances diverted cannot. Attackers understand this. The pressure to pay is higher in healthcare than almost anywhere else, and the timeline to make that decision is shorter when patient safety is actively in jeopardy.

Clinical systems carry a certification burden that industrial equipment doesn’t. Software versions get locked to regulatory approvals. Updating a patient management system or medical device integration layer means recertification, which means vulnerability windows measured in years rather than weeks. This isn’t negligence; it’s the system working as designed, and the design has a security problem baked into it.

Recovery from ransomware in an NHS trust is genuinely hard. WannaCry took some trusts weeks to recover from in 2017, and the underlying conditions (aged systems, constrained IT resources, complex clinical workflows) haven’t fundamentally changed. The complexity favours the attacker on the other side of the recovery negotiation.

Priorities for healthcare security and operational leaders

Immediate actions matter more here than comprehensive frameworks. Four things:

Check your remote access infrastructure today. Identify every VPN appliance, NetScaler gateway, and remote access endpoint. Get the firmware versions. Check them against vendor advisories. If you’re more than two patch cycles behind on Ivanti, Cisco ASA, or Citrix NetScaler, stop and fix that before anything else.

Verify your backups are actually protected. These affiliates go for backup infrastructure before triggering encryption, deliberately. Cold backups and air-gapped copies are what recovery depends on. If your backup target is reachable from your primary network, you need to change that.

Segment clinical from administrative systems. Flat networks let ransomware move through an entire estate in hours. Segmentation doesn’t stop the intrusion, but it limits what gets encrypted, and that distinction is the difference between a serious incident and a trust-wide shutdown.

Run the 72-hour scenario. What does your trust actually do if clinical systems are unavailable for three days? Not the theoretical plan, but the one your staff will actually execute at 2am on a Tuesday. Gaps in that answer are gaps in your actual resilience posture.

NHSE has issued updated guidance. Boards asking for written assurance on patch status and backup integrity from their CISO or Head of IT Security in the next two weeks is the right governance instinct here, not because a piece of paper protects anyone, but because the process of answering that question surfaces problems that need addressing.