Healthcare

SonicWall Research Sounds Code Red on Healthcare Cybersecurity as Attack Rates Refuse to Decline

New Healthcare Protect Brief reveals 13.3 million remote desktop exploitation attempts and more active ransomware families than any other tracked vertical

MILPITAS, Calif. — June 23, 2026 — SonicWall today released its 2026 Healthcare Protect Brief, a vertical-specific companion to the SonicWall 2026 Cyber Protect Report, revealing that healthcare cybersecurity remains the most persistently targeted industry in SonicWall’s global telemetry, and that the gap between healthcare and every other sector is widening, not closing.

While attack volumes across most verticals declined between 17% and 56% year-over-year, healthcare recorded the smallest decline of any tracked industry. The finding is not simply that healthcare is heavily targeted - it’s because attackers are less willing to leave healthcare than anywhere else.

"Healthcare is the most targeted industry for several reasons, and none of them are accidental," said Michael Crean, SonicWall SVP of Managed Services. "What our research makes clear is that attackers have done the math. Hospitals cannot go dark, downtime is measured in patient outcomes and the pressure to pay is unlike anything in any other sector. None of that changes until healthcare stops relying on security architectures built for a world that no longer exists, and starts treating Zero Trust not as a future initiative, but as the baseline they needed yesterday."

SonicWall’s Healthcare Protect Brief draws on data from SonicWall’s global network of more than one million security sensors to document the specific attack patterns, exploitation vectors and ransomware campaigns defining the healthcare threat landscape in 2026.

Key Findings from the 2026 SonicWall Healthcare Protect Brief

  • Healthcare recorded the smallest attack decline of any tracked vertical, just 17% year-over-year
  • UltraVNC buffer overflow attacks generated 13.3 million hits in five months, a finding unique to healthcare
  • IoT exploitation spanned 243 unique attack signatures targeting connected medical devices
  • Ten active ransomware families operated simultaneously against healthcare — more than any other vertical
  • Log4j generated 11.4 million hits despite being patched in 2021
  • Malware hits per firewall reached 102,209 in H1 2026 — four times the next-highest vertical

Three Problems. One Industry. No Easy Exits.

Healthcare's attack surface has three structural problems that attackers have learned to exploit with precision. Remote desktop tools (necessary for distributed clinics, telemedicine and third-party vendor access) generated 13.3 million UltraVNC exploitation attempts in the first five months of 2026 alone. When those tools are internet-exposed without layered controls and backed by VPN architectures that grant broad network access the moment credentials are validated, a single stolen login compromises the entire environment.

The Internet of Things (IoT) footprint makes it worse. Exploitation spanned 243 unique attack signatures targeting connected medical devices that cannot be patched, cannot run endpoint agents and share network segments with clinical systems. A Hikvision vulnerability from 2021 is still generating millions of detection events in 2026. Legacy vulnerabilities do not expire. Against that backdrop, ten ransomware families operated simultaneously against healthcare in the first half of 2026. That is not opportunism. It is a calculated market decision driven by one simple reality: healthcare cannot absorb downtime, and the pressure to pay is unlike anything in any other sector.

"Healthcare does not have a cybersecurity problem,” continued Crean. “It has three of them, and attackers have figured out how to use all of them at the same time."

The Architecture Problem Has a Known Solution

The vulnerabilities documented in the Healthcare Protect Brief are well understood, and the controls that address them exist. What slows deployment is not the technology; it is the absence of a repeatable process for standing it up across facilities that open on compressed timelines.

SonicWall Cloud Secure Edge (CSE) solves the architectural problem by applying Zero Trust principles to every access request, granting application-level access only and continuously re-verifying identity and device posture. A compromised credential no longer means a compromised network.

SonicWall partner Fornida proved that deployment at scale is achievable. Working with ExaltHealth across five operating rehabilitation hospitals and eight more in planning, Fornida embedded Zero Trust into a standardized opening playbook. It ships pre-configured with every facility's equipment package. Legacy VPN is retired facility by facility. No network rebuild required.

"What the ExaltHealth engagement taught us is that security cannot be an afterthought in a hospital opening," said Farzad Vahid, Founder and CEO, Fornida, a trusted SonicWall partner. "By the third facility, Zero Trust was built into our standard playbook. Five hospitals operating. Eight more planned. That only works if security is a system, not a fire drill."

Availability

The SonicWall 2026 Healthcare Protect Brief is available at https://www.sonicwall.com/threat-report. It is the first in SonicWall’s 2026 Vertical Series, accompanying the SonicWall 2026 Cyber Protect Report released in March 2026.

About SonicWall
For more than 30 years, SonicWall has championed a partner-first model that combines purpose-built technology, cloud-delivered security services and real-time threat intelligence to help businesses prevent breaches, reduce risk and stay operational in the face of evolving modern threats. We are committed to deliver the best security outcomes for our customers where others deliver features and functions.  Through its unified cybersecurity portfolio and global community of over 17,000 partners, SonicWall enables managed service providers to actively manage, continuously optimize and measurably protect networks, cloud environments, endpoints and applications. The company is redefining cybersecurity around outcomes that matter to business leaders, including breach prevention, compliance achievement, cost efficiency and reduced human error, because protection is not about what a product can do but about what it actually delivers.

latest stories

  • SonicWall, MSP를 위한 차세대 네트워크 보안 솔루션으로 사이버 보안을 재정의하고 새로운 기준을 정립
    계층화된 보안, 공동 관리 서비스, 통합 관리 플랫폼으로 든든한 보안을 제공하는 SonicWall은 차세대 방화벽을 활용한 지속적인 혁신으로 파트너가 수익성 있는 서비스를 키울 수 있도록 돕고 있습니다.캘리포니아주 밀피타스 — 2025년 5월 5일 — SonicWall은 날로 늘어나는 오늘 관리형 서비스 제공자(MSP) 및 고객의 포괄적인 보호 및...
    Read More
  • SonicWall 위협 데이터로 드러난 사이버 공격의 깊이 - 높아지는 관리형 서비스 제공자(MSP)의 필요성
    총 침해 공격 건수 증가(+20%), 위협 행위자의 전술 다각화 - 전 세계에서 공격 증가 랜섬웨어는 한 해 내내 거셌으며(하반기 +27%) 여름철에 절정(+37%) 총 크립토재킹 공격 건수 – 전 세계에서 +659% 급증 IoT 취약점 공격(+15%)와 암호화된 위협(+117%)도 상승세 '기존에 없었던' 맬웨어 변종 SonicWall...
    Read More
  • SonicWall, 관리형 엔드포인트 보안서비스로 확대하고 있습니다,
    SonicWall은 파트너 성장을 더욱더 촉진하기 위해 연중무휴24x7 보안운영센터(SOC)를 갖춘 관리형 탐지 및 대응(MDR) 제품군을 새롭게 확장합니다. 캘리포니아주 밀피타스 — 2024년 2월 8일 —소중한 채널 파트너의 피드백을 반영하여 SonicWall은 오늘, MSP를 위해 맞춤 구성된 여러 관리형 서비스가 제공된다고 발표했습니다. SonicW...
    Read More