Ransomware

Synnovis NHS pathology ransomware attack (Qilin)

πŸ“… 2024-06-03 🏒 Synnovis (NHS pathology services provider) 🦠 Qilin ransomware
Primary Source β†—

Incident Details

Qilin ransomware group attacked Synnovis, a joint venture providing blood testing and pathology services to King’s College Hospital NHS Foundation Trust and Guy’s and St Thomas’ NHS Foundation Trust in London. Attack date: 3 June 2024. 10,152 acute outpatient appointments and 1,710 elective procedures cancelled or postponed. Blood supply severely disrupted; O-negative and O-positive reserves depleted requiring a national NHS appeal for donations. Qilin demanded $50 million ransom; Synnovis refused to pay. 900,000+ patients affected; data published on dark web. Attack later identified as a contributing factor in a patient death. Breach notifications issued 17 months after the attack. ICO investigation ongoing.

Technical Details

Initial Attack Vector
unknown
Vendor / Product
Synnovis (NHS pathology services provider)
Malware Family
Qilin ransomware

Timeline

  1. 2024-06-03 Breach occurred
  2. 2024-06-04 Publicly disclosed
  3. 2025-11-01 Customers notified