New Cybersecurity Challenges in the Healthcare Sector

The Clusit Report on Cybersecurity in Italy and Worldwide – 2026 includes a focus section entitled The Fragility of Digital Healthcare: Rising Attacks, New AI-Driven Risks, and an Ever-Expanding Perimeter, prepared by Women For Security.
The report highlights the profound digital transformation that the healthcare sector has undergone in a relatively short period of time. While this evolution has significantly improved clinical efficiency and the quality of care, it now requires higher and more sophisticated levels of security. The main challenges lie in managing vast amounts of sensitive and confidential information, safeguarding critical systems and technologies, and protecting operations carried out through interconnected digital services.
One of the most significant factors is the introduction of resources based on agentic artificial intelligence, which bring scalability benefits and enhanced performance, but also introduce risks associated with unprecedented technologies and operational dynamics. The expansion of the perimeter to be defended—including IT systems, IoMT (Internet of Medical Things) devices, connections, and identities—results in increasingly broader areas of exposure.
From a quantitative perspective, the global data presented in the report are striking. The number of successful cyberattacks against the healthcare sector increased from 210 in 2020 to 1,053 in 2025, representing a 35% increase over the previous year and a volume five times higher than in 2020, with an average of 88 attacks per month. Geographically distributed data show a limited slowdown in the Americas and Europe, a significant increase in Asia, and the emergence of African victims, albeit in much smaller numbers. In Italy, the National Cybersecurity Agency (ACN) recorded a 47.4% increase in cyber incidents between January and December 2025 compared with the previous year.

Regarding the prevalence of specific threats, experts consistently identify malware and ransomware, phishing and social engineering campaigns, and DDoS attacks as major concerns, alongside the exploitation of vulnerabilities and system weaknesses.
The implications of a large-scale ransomware attack, such as the one that affected Change Healthcare in the United States in 2024, have already been experienced firsthand.
Among the dozens of extortion-driven attacks recently claimed against the Health & Pharma sector, one targeted the Danish pharmaceutical giant Novo Nordisk, producer of roughly half of the world’s insulin supply and the weight-loss drug Wegovy. The criminal group FulcrumSec allegedly stole information relating to thousands of company employees and physicians, as well as internal studies, and demanded a $25 million ransom to prevent the publication of the stolen data.
Perhaps even more concerning than ransomware, however, is the sophistication reached by state-sponsored threat actors. Attack techniques are evolving rapidly—again, increasingly supported by artificial intelligence—as are the motivations behind these operations. Iranian cyber campaigns targeting the U.S. healthcare sector have provided a paradigmatic example. As has already been observed, healthcare providers, research institutions, and companies operating in diagnostics and pharmaceuticals are now exposed to genuine forms of hybrid warfare. Their infrastructures are potential targets for cyberespionage and state-sponsored destructive operations that threaten both the confidentiality of national activities and public safety.
Beyond worst-case scenarios, recent weeks have revealed a cyberespionage operation tracked in the United States and Canada that demonstrates how these risks are no longer merely hypothetical. Attributed to the APT group UNC6508, believed to be linked to China, the campaign targeted, among others, world-leading clinical centers, universities, military healthcare facilities, professional advocacy organizations, and healthcare regulatory bodies. Collectively, these organizations are involved in research activities ranging from molecular discovery and pharmaceutical clinical trials to public health policymaking and military readiness.
The importance of adopting new and increasingly effective security policies has been clearly recognized by European lawmakers. The regulatory ecosystem taking shape for digital healthcare in the European Union rests on three pillars.
First, the NIS2 Directive, now fully in force, requires organizations to implement a more mature and risk-aware approach to cybersecurity management.
Second, the European Action Plan on the Cybersecurity of Hospitals and Healthcare Providers, launched in January 2025 to coordinate the efforts of healthcare providers, Member States, and the cybersecurity community, represents the first sector-specific initiative to implement the full range of EU cybersecurity measures.
Finally, the European Health Data Space (EHDS) Regulation, which entered into force in March 2025, aims to establish, through a gradual and structured process, a common framework for the use and exchange of electronic health data across the European Union.
TS-Intelligence

The information reported is the result of the collection and analysis work carried out by the specialists of Telsy’s Threat Intelligence & Response team with the support of the TS-Intelligence platform, a proprietary, flexible, and customizable solution that provides organizations with a detailed risk landscape.
It is available as a web-based and full-API platform, designed to be integrated into the organization’s systems and defensive infrastructures, with the goal of enhancing protection against complex cyber threats.
The platform’s continuous research and analysis on threat actors and emerging online threats—whether APTs or cybercrime—produces a constant stream of exclusive intelligence, delivered in real time and structured into technical, strategic, and executive reports.
Discover more about our Cyber Threat Intelligence services.