Threats · 18h ago

Belarusian Hackers Hid in a Russian Health Network

Solar says it found a nearly two-year intrusion in a Russian healthcare network in December 2025 and traced the earliest signs back to early 2024, attributing it to the Belarusian Cyber Partisans. The targeted organization was not named, but Solar said it had broad infrastructure tied to many other healthcare organizations.

The attackers did not smash systems or trigger obvious outages; Solar said they kept the access quiet and used it for espionage, with one likely use being trusted-relationship attacks. In plain terms, if a provider network is already linked to other providers, compromise of the hub can become a path into those downstream organizations and their patient data.

For healthcare operators, the lasting risk is not just the breached network itself but every partner network that trusted it. A long-lived intrusion like this can preserve access precisely because it avoids disruption, so the blast radius may include organizations that were never directly touched.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-10-06

Editions

Related stories