TRANSMISSION ACTIVE
// FREQ: HEALTHCARE EPISODE: 026 STATUS: SECURE

026 World Leaks Extortion, Quishing Attacks, and Inside the Latest Health-ISAC Threat Briefing

This week our CISO brings you somewhere most healthcare leaders never get to go: inside a nationwide Health-ISAC threat briefing, the healthcare sector's own member-only intelligence-sharing call. She walks through the two threats the sector is tracking right now — the World Leaks data-theft extortion group that steals and leaks regardless of whether you pay, and the quishing, ClickFix, and FileFix social-engineering attacks slipping past the training your people already had. Then she takes you into a sector-wide business continuity exercise run across more than 500 organizations, and the uncomfortable lessons it surfaced. The throughline: you were never meant to defend alone. The organizations that plug into sector intelligence and act on it see the threat coming. The isolated ones find out when it's already inside.

JUMP POINTS //

01:06

World Leaks: Extortion That Doesn't Respect Industry

The data-theft extortion group profiled in Health-ISAC’s Q2 2026 Heartbeat. They steal your data and leak or sell it regardless of whether you pay — which means backups don’t save you. And they don’t care what sector you’re in: patient records, CUI, source code, financial data all monetize the same way.

03:51

Quishing, ClickFix, and FileFix — Why QR Codes Beat Your Filters

A QR code is an image, so it sidesteps the URL scanning that catches traditional phishing. The payload only resolves when someone scans it — usually on a personal phone outside your controls. Attackers make one code, send it out, and catch whoever doesn’t stop to think.

05:32

Three Moves Against Both Threats

Treat every QR code like an unknown email link. Assume the breach is a leak, not a lockout — minimize and encrypt. And plug into your sector’s ISAC, because you can’t watch the whole battlefield alone.

06:59

What Health-ISAC Actually Is — And Why You Can't Just Join

The Health Information Sharing and Analysis Center: a vetted, member-only, organization-based network where healthcare shares threat data it never posts publicly. Real-time alerts, indicators, and defensive collaboration — with more than 1,200 targeted alerts distributed to the sector last year alone.

09:00

Why This Is Patient Safety, Not IT

When the prescription can’t reach the pharmacy, when a hospital goes down and has to divert — but every nearby hospital is down too — the consequences are measured in patient care, not downtime. This is the framing that separates healthcare from every other sector.

11:16

The Exercise: When the Shared Cloud Provider Goes Down

The sector-wide business continuity scenario — a compromised cloud identity provider cascading across everyone at once. How long can you limp along on manual workarounds? And where are you in the incident-response queue when a hundred other organizations need the same ten analysts?

16:22

Teach the Teacher: What to Do With All of This

Vary who runs your business continuity exercise. Build a real threat-intel program. Understand where you actually rank in the sector. And the root cause underneath everything: it always comes back to people, staffing, and budget.

// INCOMING SITREP

The episode covers the threats and the intelligence-sharing model. The companion Sitrep goes deep on the exercise itself — the shared-cloud-provider scenario that breaks most continuity plans, the redirect that fails when every hospital is down, and the incident-response retainer that's worthless when a hundred victims hold the same one. Read the SITREP dossier.

ACCESS THE BRIEF »

TRANSMISSION LOG //

A Different Kind of Episode

Most weeks, we bring you the intelligence. This week, our CISO brought you into the room where the healthcare sector shares its own.

She sat in on a nationwide Health-ISAC threat briefing — a member-only, sector-wide call that included a business continuity exercise with more than 500 participants from healthcare organizations across the country. This transmission covers the two threats the sector is actively tracking, what a call like that is actually for, and the uncomfortable lessons a sector-wide disaster scenario surfaced.

World Leaks: The Extortion Model That Ignores Your Industry

The first threat is a group called World Leaks, profiled as a distinct threat-actor priority in Health-ISAC’s Q2 2026 Health Sector Heartbeat. (The “Heartbeat” is Health-ISAC’s quarterly situational-awareness report — the sector’s pulse check.)

Their model is pure data-theft extortion, and it’s the evolution we covered in Episode 025. They don’t just encrypt your data and demand a ransom to unlock it. They steal it, then threaten to leak it — and they’ll sell it or dump it on the dark web whether or not you pay. That’s the critical distinction: backups don’t save you from a leak. You can restore every system perfectly and your patient data is still out there being monetized.

And here’s why it matters to every listener, not just healthcare: extortion doesn’t respect industry lines. Every sector has data worth stealing. Healthcare has patient records. GovCon has CUI and classified information. Tech has customer data and source code. Finance has account and accounting data. World Leaks — and groups like it — will target anyone. They simply tailor the attack to each sector’s known weaknesses, because organizations within a sector tend to share the same vulnerabilities.

That last point is the entire argument for sector-level intelligence sharing. If your peers share your weaknesses, they also share your early warnings.

Quishing: Why a QR Code Beats Defenses That Used to Work

The second threat sounds almost too simple to be dangerous — and that’s exactly why it works.

Quishing is QR-code phishing: embedding a malicious link inside a QR code image. Alongside it are newer deception techniques like ClickFix and FileFix. All of them exploit human behavior rather than technical vulnerabilities.

Here’s the mechanic that makes quishing so effective: a QR code is an image, so it sidesteps URL scanning. The email filters and link-detection tools that catch traditional phishing never see the payload, because there’s no readable link to scan — just a picture. The malicious URL only resolves when the victim scans the code, usually on a personal phone that sits entirely outside your organization’s security controls.

And the behavioral reality is grim. People scan QR codes reflexively — even security professionals. You see them everywhere: on conference badges, on fliers, on advertisements, exchanged between people who just met. Nobody stops to think. Attackers know this. They make one code, send it out, and catch whoever doesn’t pause. It’s low-effort and high-yield, and it feeds the same machine as everything else — harvesting the credentials and access that data-theft extortion groups need to get in. Same two-door pattern from Episode 025, just an easier door.

Three Moves Against Both Threats

Our CISO’s universal marching orders:

Treat every QR code like an unknown link in an email.

Security awareness training already taught people not to click random links. Extend that instinct to QR codes — and use one of the apps that safely previews where a code actually sends you before you go there.

Assume the breach is a leak, not a lockout.

Minimize and encrypt your sensitive data so a data-theft group has less to sell. This is already a control requirement across most sectors — treat it like one.

Plug into your sector’s ISAC.

Information Sharing and Analysis Centers exist for every critical-infrastructure sector — Health-ISAC for healthcare, FS-ISAC for finance, and so on. Being connected is how our CISO was in the room for a 500-organization exercise in the first place.

What Health-ISAC Actually Is

Health-ISAC — the Health Information Sharing and Analysis Center — is a nonprofit, member-driven organization that shares cyber and physical threat intelligence across the global health sector. ISACs exist for most critical-infrastructure sectors (healthcare, bulk electric utilities, finance, and more).

A few things worth knowing that surprise people:

You can’t just join. It’s not public. When you request membership, they validate who you are first. And it’s organization-based — a hospital or a payer joins as an organization, and then that organization’s employees gain access. You don’t join as an individual.

It’s a trusted, member-only channel. These are real-time alerts, indicators, and defensive collaboration that organizations share precisely because they’d never post it publicly. When something hits the sector, Health-ISAC is one of the fastest ways to know — especially when an incident is spreading across multiple organizations at once. Last year alone, the network distributed more than 1,200 targeted alerts to the sector.

Why This Is Patient Safety, Not IT

Healthcare is one of the most targeted sectors on earth, and the reason is severity of consequence. Health-ISAC’s own leadership frames these incidents as patient-safety and business-continuity crises, not IT events — and that framing is the whole ballgame.

Our CISO made it concrete. Imagine you can’t get a life-sustaining medication because your doctor’s system can’t transmit the prescription, or the pharmacy received it but can’t get insurance authorization to release it — so you wait, or you pay hundreds of dollars out of pocket. Now scale that up. A hospital’s systems go down mid-emergency. Hospitals can stand up emergency capacity fast. But if they’re overwhelmed, the fallback is to divert patients to another hospital — and if every nearby hospital is fighting the same outage, where does the patient go?

That question is the bridge into the exercise, and it’s the subject of our companion Sitrep.

Inside the Exercise: When the Whole Sector Goes Down at Once

The business continuity exercise put a scenario on the table that most organizations never model: a cloud identity and credential provider — the kind of hyperscale platform that hosts login and identity for a huge share of the sector — begins to degrade and shows signs of compromise.

Why that’s catastrophic: your credential service is your identity layer, and in a modern environment your identity provider is the hub everything connects through. Applications, integrations, vendor connections, SaaS platforms — they all authenticate against it. When it degrades, you don’t lose one system. Your whole technology stack starts going dark.

And it’s not just you. Everyone on that cloud provider is hit simultaneously — plus their vendors and suppliers, who are probably on the same infrastructure. The exercise forced participants to sit with the questions a siloed plan never asks: How long can you actually limp along on manual workarounds before patient care suffers? And if you hold an incident-response retainer, where are you in the queue when a hundred other organizations are calling the same firm’s ten analysts at the same moment?

Those questions — the limp-along ceiling, the failed hospital redirect, and the oversubscribed IR retainer — are exactly what our companion Sitrep breaks down in full, along with how to build a continuity plan that actually accounts for them.

Teach the Teacher: What To Do With This

Asked to distill it for listeners who weren’t on the call, our CISO’s guidance:

Vary who runs your business continuity exercise.

If the same internal team runs it every year, you rehearse the same assumptions every year. Bring in an outside facilitator periodically — a different perspective injects scenarios your team is blind to, because you can’t predict how a real event will unfold. You can only prepare for a wider range of them.

Build a real threat-intelligence program.

If you don’t have one, you need one. You need eyes on the ground and ears listening for you, because you can’t watch the whole battlefield yourself. Join the ISACs. Assign someone to own the intel.

Understand where you rank.

Every organization believes it’s critical. But zoom out to the sector and the hierarchy is clear — direct patient care takes precedence over back-office functions when everyone is competing for the same resources. Plan for the position you’ll actually be in.

And the root cause underneath all of it: people.

As our CISO put it bluntly — it always comes back to people. Staffing and budget are the deciding factor, not technology. Intelligence you can’t action because you’re understaffed is intelligence wasted. This is exactly why smaller and rural organizations increasingly lean on outside partners and intelligence networks — because they can’t build it all in-house, and realistically never will. That’s not a failure. It’s a rational response to an asymmetry no single organization can beat alone.

The Bottom Line

From World Leaks to quishing to the third-party exposure the whole sector keeps flagging, the theme of this episode is simple: you are not defending alone, and you were never supposed to.

Plug into your sector’s intelligence. Act on it. And you’ll see the threats coming — instead of finding out you were isolated at the exact moment you’re already breached.

Mission success starts with knowing what your peers already know.

Go Deeper: The Business Continuity Breakdown

This episode covers the threats and the intelligence-sharing model. Our companion Sitrep goes deep on the exercise itself — the shared-cloud-provider scenario that breaks siloed continuity plans, why the redirect-to-the-next-hospital plan fails in a sector-wide event, the incident-response retainer that’s worthless when a hundred victims hold the same one, and the specific steps to build resilience that accounts for the environment you actually operate in.

Trust but verify your own posture. Plug into your ISAC. Action this quarter’s threats. Re-verify your vendors. Execute the standard.

// DECODED TRANSCRIPT

Access the full text logs of this transmission for compliance and review purposes.

SILENCE THE NOISE. AMPLIFY THE SIGNAL.

INTELLIGENCE IS USELESS IF YOU AREN'T LISTENING.

Join The Watch to receive New Episode Alerts, Strategic Breakdowns, and Guest Intel delivered to your inbox.