On July 20, 2026, Health-ISAC released its Health Sector Heartbeat for the second quarter of 2026, a situational-awareness report examining cyberthreat activity that could affect healthcare and related organizations.
What happened
The report brings together Health-ISAC’s (Information Sharing and Analysis Center) observations of ransomware incidents, broader cybercrime trends, and posts by malicious actors on underground forums. Its scope includes ransomware attacks involving the health sector, patterns identified through targeted alerts, and activity occurring in criminal online communities. Health-ISAC also profiles World Leaks, a cyberthreat group highlighted in the quarterly assessment, and provides mitigation strategies intended to help organizations reduce their exposure.
Rather than announcing a single breach or attack, the publication offers a sector-wide view of the threats observed during the quarter and the behaviors defenders should monitor. Health-ISAC states that the material is intended for situational awareness and recommends that members connected to identified victim companies or organizations that could be affected take appropriate steps to secure critical infrastructure. The report also directs readers to related cybersecurity resources covering threat sharing, incident response, artificial-intelligence supply chain risk, organizational crisis readiness, and human risk management.
Going deeper
One of the most consequential sections of Health-ISAC’s Q2 2026 Health Sector Heartbeat is its dedicated threat-actor profile of World Leaks. By calling out the group alongside ransomware incidents, targeted alerts, and underground-forum activity, Health-ISAC signals that healthcare security teams should treat World Leaks as a distinct intelligence priority and reassess how they protect sensitive data, credentials, and third-party access.
Paubox’s 2026 Healthcare Email Security Report points out the broader weaknesses that make the sector attractive to extortion groups. One hundred and seventy healthcare email-related breaches were reported in 2025, affecting 2.5 million individuals. Of those incidents, 28% involved vendor or business-associate email exposure, while 17% resulted from phishing-driven mailbox takeovers.
Paubox’s separate Healthcare Email Security Maturity Index found that 58% of surveyed healthcare organizations had experienced an email-related breach during the previous 24 months, including 23% that were breached more than once. These figures are not attributed specifically to World Leaks, but they demonstrate the compromised identities, exposed communications, and third-party weaknesses that can give cybercriminals access to valuable healthcare data.
By the numbers
The report noted, “Health-ISAC identified 2,755 total events across all critical infrastructure sectors in the second quarter of 2026. 4,860 incidents were recorded in the second half of 2025, indicating that 2026 will likely be a recordbreaking year if the trend continues. The total number of incidents in H1 of 2026 (5,672) exceeded the total in H2 of 2025 (4,860), representing a 17% increase. In 2025, 590 incidents specifically impacted the health sector. H1 of 2026 experienced 402 health-sector-specific incidents.”
Among the regionally classified all-sector records:
- Americas: 1,012 entities (53.6%)
- EMEA: 543 (28.7%)
- APAC: 334 (17.7%)
Health-sector records offered the following:
- Americas: 136 entities (72.3%)
- EMEA: 33 (17.6%)
- APAC: 19 (10.1%)
The report also noted targeted alerts and world leaks as:
- Health-ISAC issued 193 targeted alerts to member organizations during Q2.
- 92 alerts concerned misconfigured or dangling DNS records.
- World Leaks had listed at least two dozen health-sector victims, most of which were hospitals.
- Its journalist portal reportedly gives media organizations 24 hours’ advance access to stolen information.
Why it matters
Hospitals depend on electronic records, laboratory systems, imaging platforms and connected communications to coordinate treatment; when those systems become unavailable, clinicians may have to delay procedures, divert patients or rely on slower manual processes. The effects can also extend beyond the organization directly attacked. A JAMA Network Open study found that nearby, unaffected emergency departments experienced greater patient volumes, longer waits and pressure on time-sensitive stroke care during a ransomware attack on another health system.
The researchers concluded that “targeted hospital cyberattacks may be associated with disruptions of health care delivery at nontargeted hospitals within a community.” Health-ISAC’s upward trend should therefore be understood as a warning about expanding operational and patient-safety exposure, not merely a higher number of technical security events. Although not every reported incident causes clinical disruption, a growing attack environment increases the need for healthcare organizations to strengthen prevention.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
How are cyber extortion tactics changing in 2026?
Some groups increasingly steal data and threaten publication without encrypting systems.
Are backups enough to protect against ransomware?
No, backups can support system restoration, but they cannot prevent attackers from stealing information, compromising accounts or threatening to publish data.
Does every cyber incident constitute a reportable HIPAA breach?
A security incident does not automatically become a reportable breach. The organization must determine whether unsecured protected health information was accessed, acquired, used or disclosed impermissibly and conduct the required HIPAA risk assessment when applicable.
