Spencer Starkey, executive vice president, EMEA, at SonicWall, says that our hospitals are being stress-tested to breaking point.

Here’s a number that should stop every NHS trust board mid-meeting: 264,000. That’s how many individual intrusion attempts threat researchers logged against UK healthcare networks between January and May this year. For context, the whole of 2025 saw 27,000. That’s a startling tenfold surge compressed into less than half the time. And it’s still climbing.

Down at the device level, it is even worse. Every sensor monitoring a UK healthcare network is now absorbing roughly 11,000 attack events. No other sector in Britain is anywhere close. Retail, finance and manufacturing – none of them is being hit with this kind of relentless, focused pressure. These verticals are facing their own issues, but healthcare has become the most targeted industry in the country.

So why aren’t the alarm bells louder? Because the attackers aren’t tripping any alarms at all, that’s the part that should genuinely worry us.

If you’ve followed cybercrime trends over the past couple of years, you’ll know ransomware volumes fell sharply in 2025 – down 87% across UK businesses. Standard threat actors (industry term for hackers) are losing interest, while the sinister “Big Game Hunters” are getting smarter. They stopped spraying attacks everywhere and started picking fewer, richer targets, going in for bigger single payouts instead of volume.

Healthcare doesn’t quite fit into the mould. What we’re seeing instead is something more patient and, frankly, more unsettling: zero confirmed ransomware activations against this wave of activity. No lock screens or ransom notes. Just quiet, methodical reconnaissance – attackers mapping hospital networks, probing their supply chains, working out exactly where the weak points sit. Not exactly a smash and grab. Surveillance at this scale usually precedes something bigger.

Cyber attacks in healthcare

Zombie tech won’t die

A huge chunk of this activity – 41% of it, 107,708 hits – is exploiting Log4j. The honest assessment is that attackers are still walking through a front door that’s been unlocked for years, using a vulnerability the industry has known about since 2021. 

What makes it worse is that it isn’t exactly a sophisticated zero-day – a security flaw in software that the people who made the software don’t know about yet – it’s a flaw sitting quietly inside legacy Java middleware that administrators haven’t been able to patch, or haven’t bothered to or haven’t had the resources available. 

In a lot of cases, nobody can patch it. In the more extreme cases, you can’t take a critical care system offline for maintenance when it’s running life-support monitoring or diagnostic imaging. Clinical continuity has to win over IT hygiene, every single time, and everyone, attackers included, knows it. 

They’re exploiting an impossible trade-off. The term is: zombie tech – ancient, unpatched, technically dead-but-walking infrastructure that keeps shuffling along because pulling the plug isn’t an option. It haunts the NHS because it has to.

Layer onto that the 33% of sensors seeing active attacks against F5 BIG-IP, which is hardware/software that sits in front of a company’s servers and manages traffic – bouncer and air traffic controller rolled into one. You’ve got adversaries hitting both the old foundations and the modern edge of hospital infrastructure at once.

The push to digitise – patient portals, online booking, remote monitoring, all built on modern frameworks like React and Next.js – has been broadly good for patients and desperately needed. Everyone has waited for a GP appointment far longer than they should have. But speed and security don’t always travel together, and we’re now seeing fresh vulnerabilities in these newly deployed frontline services being actively targeted.

Attackers are working two flanks simultaneously: decades-old middleware nobody can safely patch, and brand-new web infrastructure that hasn’t had time to harden. That gap between old and new is the entire attack surface, and threat actors have sussed it. They’re scanning for it relentlessly, methodically and, crucially, without geopolitics driving the timeline.

This exploitation wave started before recent geopolitical flashpoints, including the escalation around Iran. What could be opportunistic noise riding on the back of a news cycle, it is actually tracked far more closely with a global uptick in targeting of critical infrastructure and operational technology. In other words, healthcare is being treated as critical national infrastructure (CNI) by the people attacking it. 

Spencer Starkey, executive vice president, EMEA, at SonicWall.
Spencer Starkey, executive vice president, EMEA, at SonicWall.

What needs to change

As much as many in cyber would love there to be, there is no silver bullet for infrastructure this complex, this constrained and this exposed. However, acting and planning according to the following three steps needs to happen faster than current speeds. 

First, visibility has to improve. You cannot defend a network you can’t see, and reconnaissance-stage attacks are only detectable if someone’s actively watching for the probing, and not only the resultant payload. 

Second, segmentation matters more than ever. If a legacy system genuinely can’t be patched, it needs to be isolated so a compromise in one spot doesn’t become a compromise everywhere.

Third, and most difficult: procurement and security teams need to be on the same page when new patient-facing services go live. The rush to digitise is right and absolutely needed, but to digitise without security baked in from day one is how you end up on the wrong side of a headline.  

As it stands, UK healthcare is being stress-tested at a scale and intensity no other sector is experiencing. There is nothing reassuring about the silence. It’s covert reconnaissance with a delayed sting in the tail.