Threats & Adversaries · APT / Espionage

Belarusian Hackers Hid in a Russian Health Network

Solar says it found a nearly two-year intrusion in a Russian healthcare network in December 2025 and traced the earliest signs back to early 2024, attributing it to the Belarusian Cyber Partisans. The targeted organization was not named, but Solar said it had broad infrastructure tied to many other healthcare organizations.

The attackers did not smash systems or trigger obvious outages; Solar said they kept the access quiet and used it for espionage, with one likely use being trusted-relationship attacks. In plain terms, if a provider network is already linked to other providers, compromise of the hub can become a path into those downstream organizations and their patient data.

For healthcare operators, the lasting risk is not just the breached network itself but every partner network that trusted it. A long-lived intrusion like this can preserve access precisely because it avoids disruption, so the blast radius may include organizations that were never directly touched.

1 source · 19h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-06

Every edition of this story: Belarusian Hackers Hid in a Russian Health Network

More from today