Supply chain β›“ Supply Chain

NHS England Third-Party Breach (September 2024)

πŸ“… 2024-09-01 🏒 Synnovis
Primary Source β†—

Incident Details

Data on nearly 1 million NHS patients leaked online following ransomware attack on London hospitals. The stolen data, which was published in June by the Qilin ransomware gang, includes requests for appointments as well as for pathology and histology tests. It features in many cases details of symptoms for sensitive medical conditions that patients may not yet know have been exposed. People with symptoms of sensitive medical conditions, including cancer and sexually transmitted infections, are among almost a million individuals who had their personal information published online following a ransomware attack that disrupted NHS hospitals in London earlier this year, according to an analysis shared with Recorded Future News. Third-party company: Synnovis.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Synnovis
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-09-01 Breach occurred
  2. 2024-09-16 Publicly disclosed