London Hospitals Hit by Major Cyber-Attack: Patient Data Exposed

A notorious gang of cyber criminals has caused significant disruption to several London hospitals by publishing sensitive data stolen from an NHS blood testing company.
On Thursday night, the hacker group known as Qilin released nearly 400GB of private information on their darknet site. This follows their hack of NHS provider Synnovis on June 3, from which they have been trying to extort money.
Qilin had previously threatened to release the data if their demands were not met. A sample of the leaked data, reviewed by the BBC, includes patient names, dates of birth, NHS numbers, and descriptions of blood tests. However, it is unclear if the test results are part of the leaked data. The leaked information also contains business account spreadsheets detailing financial arrangements between hospitals, GP services, and Synnovis.
NHS England confirmed they are aware of the publication but cannot verify the authenticity of the shared data. They are working with Synnovis, the National Cyber Security Centre, and other partners to determine the content of the published files and whether it includes data from the Synnovis system.
Synnovis expressed their concern over the development, stating: “We know how worrying this development may be for many people. We are taking it very seriously and an analysis of this data is already underway.”
The Synnovis hack is one of the most severe cyber-attacks in the UK, affecting over 3,000 hospital and GP appointments and operations due to the disruption in pathology services. The ransomware hackers infiltrated the company’s computer systems used by two NHS trusts in London, encrypting crucial information and rendering IT systems useless. They also downloaded private data to further extort the company for a ransom in Bitcoin.
It remains unknown how much money Qilin demanded or if Synnovis entered negotiations. The publication of the data suggests that no ransom was paid. Law enforcement agencies globally advise against paying ransoms as it fuels criminal enterprises and does not guarantee the return of data.
Brett Callow, a ransomware expert from Emsisoft, highlighted that healthcare organizations are increasingly targeted because they can cause significant harm and sometimes result in substantial ransoms. He noted that the healthcare sector is particularly vulnerable, especially after United Health Group reportedly paid a $22m ransom earlier this year.
On Tuesday night, Qilin communicated with the BBC via an encrypted messaging service, stating they targeted Synnovis to punish the UK for not providing enough support in an unspecified war. The group claimed the cyber-attack was a form of protest and expressed regret for the harm caused but deflected blame onto the UK government.
Qilin’s claims of activist motives are met with skepticism. The gang, believed to be based in Russia, has a history of leaking data from various sectors, including healthcare, schools, companies, and councils, for financial gain. Their recent statement criticized the UK government’s lack of support for those “fighting on the front edge of the free world,” language reminiscent of the conflict between Ukraine and Russia.
Researchers have noted that Qilin has previously recruited hackers through advertisements in Russian. While it is rare, some of Qilin’s activities could be linked to Ukraine, where many ransomware hackers have been arrested recently. Arrests in Russia are rare as the government there often refuses to cooperate with Western law enforcement.
Qilin declined to provide further details about their political allegiance or geographical location, citing security reasons.