A group of cybercriminals has caused significant disruption to multiple London hospitals by publishing sensitive patient data stolen from an NHS blood testing company. Overnight on Thursday, the group known as Qilin shared almost 400GB of private information on their darknet site. They have been attempting to extort money from NHS provider Synnovis since hacking the company on June 3rd.
Cybersecurity expert Ciaran Martin described this as “one of the most significant and harmful cyber attacks ever in the UK.” The BBC reviewed a sample of the leaked data, which includes patient names, dates of birth, NHS numbers, and descriptions of blood tests, though it is unclear if test results were included.The attack has disrupted more than 3,000 hospital.
Mr. Martin, former head of the National Cyber Security Centre and now a professor at Oxford University, mentioned on BBC Radio 4’s World at One programme that it could take several months to restore the systems. Qilin had previously threatened to publish the data unless paid.
The leaked data also includes business account spreadsheets detailing financial arrangements. NHS England acknowledged the data publication but could not confirm its authenticity. They stated they are working with Synnovis, the National Cyber Security Centre.
Synnovis expressed concern over the situation. The ransomware attack involved hackers infiltrating the company’s computer system. It serve two NHS trusts in London, and encrypting critical information to render IT systems inoperable. They also downloaded as much private data as possible to extort a ransom payment in Bitcoin.
The amount demanded by the hackers is unknown. It is unclear if Synnovis entered negotiations. However, the publication of some, if not all, of the data suggests they did not pay. Law enforcement agencies worldwide advise against paying ransoms. According to them, it perpetuates criminal activities. Also, it does not guarantee compliance from the hackers.
Ransomware expert Brett Callow from Emsisoft noted that healthcare organizations are increasingly targeted because of the potential for significant disruption and high payouts. He pointed out that since United Health Group reportedly paid a $22 million ransom earlier this year, the healthcare sector has become a more prominent target.
On Tuesday night, Qilin communicated with the BBC via an encrypted messaging service, claiming they targeted Synnovis to punish the UK for not providing enough assistance in an unspecified conflict. Mr. Martin dismissed this claim as “absolute garbage,” stating that the group’s motives were purely financial.
The gang, believed to be based in Russia, declined to specify their political allegiance or geographic location for security reasons. Their darknet site also contains stolen data from other healthcare organizations, as well as schools, companies, and councils worldwide.
Saira Ghafur, an expert in healthcare cybersecurity at Imperial College London, described this as one of the most significant cyber attacks on the NHS, predicting that the impact on patient care will be felt for weeks. She emphasized that we are now in an era where it is a matter of when, not if, cyber attacks will occur, and highlighted the need for systems to be resilient enough to withstand multiple simultaneous shocks as such attacks become more common.


