Back Health-Isac Health-ISAC reports 55% surge in cyber incidents in 2025
Health-ISAC’s 2025 Fourth Quarter Health Sector Heartbeat shows a sharp rise in cyber incidents, pointing to continued escalation into 2026. A total of 4,043 incidents were recorded across all sectors in the first half of 2025, increasing to 4,860 in the second half. With 8,903 incidents logged for the full year, activity surpassed 2024 levels of 5,744, marking a 55% increase year over year. Incidents affecting the health sector also climbed, though at a slower pace. In 2025, 585 health-sector incidents were recorded, up from 476 in 2024, a 21% increase.
During the last quarter, Health-ISAC issued 183 targeted alerts to member organizations with potentially vulnerable infrastructure, focusing on risks such as open and exposed databases, exposed remote access tools, vulnerable Ivanti Endpoint Manager instances, and Windows Server Update Services remote code execution flaws. The most common themes of Targeted Alerts sent in Q4 of 2025 included the vulnerable Ivanti Endpoint Manager Critical XSS Vulnerability, open and exposed databases, remote access tools, and Remote Code Execution (RCE) bugs in Windows Server Update Services (WSUS).
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
