Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatphishing-campaign-intelligenceransomware-group-operationcybersecurity-regulation

Reports Highlight Identity, Supply-Chain, and Healthcare as Key Cyber Risk Drivers

Updated 3mo agoFirst seen Jan 31, 20262 sources

Recent reporting highlights a shift in enterprise cyber risk toward external dependencies and identity abuse. Coverage of the EU’s NIS2 directive emphasizes that organizations are expected to treat supply-chain security as a core governance and architecture issue, reflecting the reality that third parties (e.g., cloud providers, software suppliers, maintenance access, and outsourced services) are frequent intrusion paths rather than risks contained “inside the firewall.” Separately, findings cited from Eye Security’s State of Incident Response Report 2026 indicate attackers are increasingly exploiting existing access rather than “hacking in,” with identity-based attacks dominating and passwords implicated in the vast majority of such incidents; common initial compromise paths still include phishing, exposed/misconfigured internet-facing systems, social engineering, and software supply-chain attacks.

In healthcare, a Trellix threat intelligence report based on 54.7 million detections from 2025 healthcare environments warns cyber incidents are escalating from IT disruption into a patient safety issue due to highly interconnected systems and “cascading” outages. The report identifies email as the leading threat vector and the U.S. as the primary target, and describes ransomware and extortion activity intensifying, including groups such as Qilin (noted for targeting EHR databases), INC Ransom, and newer actors like Sinobi focusing on biotech; it also reports a sharp rise in extortion-only tactics with per-patient ransom demands intended to sidestep corporate insurance dynamics. Across these sources, phishing remains a dominant initial access method, with lures increasingly tailored to privileged IT roles (e.g., “AI Transformation” themes).

Share:
Reports Highlight Identity, Supply-Chain, and Healthcare as Key Cyber Risk Drivers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 30, 20265mo ago

NIS2 pushes organizations to reassess supply-chain security responsibilities

The article says the NIS2 directive requires CISOs to give greater weight to supply-chain and third-party security. It describes a shift from focusing only on internal systems to managing external dependencies as part of security architecture and executive governance.

CSO article highlights third-party attacks as a long-running supply-chain risk

A CSO Online article states that attacks have increasingly been carried out via third parties for years, including through software updates, maintenance access, and outsourced services. It frames supply-chain exposure as a structural cybersecurity risk rather than a new isolated trend.

Jan 29, 20265mo ago

Eye Security says common initial access methods remain largely unchanged

Despite the rise in identity abuse, Eye Security assesses that attackers' core initial compromise methods have remained broadly consistent. The report cites phishing, exploitation of misconfigured or vulnerable internet-facing systems, social engineering, and software supply-chain attacks as the main entry vectors.

Attackers increasingly shift to identity-based intrusions, Eye Security reports

Eye Security's State of Incident Response Report 2026 says cyberattacks against companies are increasingly carried out through abuse of existing access rather than direct system compromise. The report states identity-based attacks dominate incident response cases, with 97% of those incidents involving passwords.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.