Supply chain
β Supply Chain
NHS England Third-Party Breach (September 2024)
Primary Source βIncident Details
Data on nearly 1 million NHS patients leaked online following ransomware attack on London hospitals. The stolen data, which was published in June by the Qilin ransomware gang, includes requests for appointments as well as for pathology and histology tests. It features in many cases details of symptoms for sensitive medical conditions that patients may not yet know have been exposed. People with symptoms of sensitive medical conditions, including cancer and sexually transmitted infections, are among almost a million individuals who had their personal information published online following a ransomware attack that disrupted NHS hospitals in London earlier this year, according to an analysis shared with Recorded Future News. Third-party company: Synnovis.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Synnovis
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-09-01 Breach occurred
- 2024-09-16 Publicly disclosed