Tens of thousands of NHS patients across the East of England have had their personal data stolen in the fallout from the June 2024 ransomware attack on Synnovis, a third-party pathology and testing provider serving NHS hospitals and GPs. The Russian cyber-criminal group Qilin uploaded roughly 400GB of sensitive information to its darknet leak site after the intrusion. The incident, described by experts as one of the most significant and harmful cyber-attacks ever carried out in the UK, has continued to widen, with trusts in Essex, Bedfordshire, London and now Norfolk all confirmed as affected.
What Happened
In June 2024, criminals broke into the computer systems of Synnovis, a provider that tests blood, tissue, and other samples and performs laboratory diagnostics for NHS hospitals and GPs. According to Synnovis, the attackers gained access in an attempt to extort the company for money in a classic ransomware playbook. When extortion efforts stalled, Qilin published approximately 400GB of stolen data to its darknet site.
The blast radius has grown steadily in the two years since. King's College Hospital NHS Foundation Trust and Guy's and St Thomas' NHS Foundation Trust were the first to disclose impact. On 2 June it emerged Bedfordshire Hospitals NHS Foundation Trust had nearly 33,000 records stolen. Mid and South Essex NHS Foundation Trust later confirmed 2,380 of its records were affected, and the BBC has now learned patients at Norfolk and Norwich University Hospitals Foundation Trust were also caught in the breach. Synnovis said in March that it had notified the organisations whose data had been affected.
What Was Taken
Qilin exfiltrated around 400GB of sensitive information from Synnovis hard drives. Synnovis characterised the theft as having been carried out "in haste and in a random manner," meaning the stolen material was not cleanly curated but pulled in bulk from computer drives. Given Synnovis processes blood, tissue, and diagnostic samples, the exposed records carry the potential for highly sensitive health-related and personally identifiable information.
Confirmed record counts so far include nearly 33,000 records at Bedfordshire Hospitals and 2,380 at Mid and South Essex, on top of earlier disclosures at the London trusts. NHS England, when asked which trusts had patient data stolen and how many individuals were affected, referred inquiries back to Synnovis, indicating the full scope of impacted individuals is still being tallied.
Why It Matters
This breach demonstrates how a single third-party supplier can become a systemic point of failure across an entire national health system. One compromise at Synnovis cascaded into patient-data exposure spanning multiple NHS trusts in different regions, and the list of affected organisations is still growing two years later. For defenders, it is a stark reminder that an organisation's risk surface extends to every vendor that touches sensitive data.
The healthcare sector remains a priority target for financially motivated ransomware crews because of the criticality of its operations and the sensitivity of its data. Qilin told the BBC via an encrypted messaging service that it had deliberately targeted Synnovis to "punish" the UK over an unspecified war, but cyber security expert Ciaran Martin dismissed that claim as "absolute garbage," stating the group's aims were "entirely financial." Defenders should treat the political framing as cover and plan against the real motive: extortion-driven data theft.
The Attack Technique
Public reporting confirms this was a ransomware and data-exfiltration operation run by Qilin, a Russian cyber-criminal group, with the specific initial-access vector not disclosed in the reporting. The hallmarks are consistent with Qilin's known double-extortion model: compromise the victim's systems, steal data in bulk, and pressure for payment under threat of public leak. When Synnovis did not pay, Qilin followed through by posting the stolen 400GB to its darknet site.
The fact that data was described as taken "in haste and in a random manner" suggests the attackers prioritised rapid bulk exfiltration over selective targeting, a pattern common when operators want to maximise leverage before detection or containment. Even without a confirmed entry point, the case underscores the importance of hardening third-party and supply-chain access paths.
What Organizations Should Do
- Inventory and risk-rank every third-party processor that touches patient or sensitive data, and require contractual security commitments, breach-notification timelines, and audit rights.
- Segment networks and enforce least-privilege access so that a compromise at a single supplier or system cannot cascade across trusts or business units.
- Deploy and monitor endpoint detection and response (EDR) tuned to flag bulk data staging and large outbound transfers, which are early indicators of exfiltration.
- Maintain tested, offline, immutable backups and a rehearsed incident-response plan so operations can recover without paying extortion demands.
- Enforce phishing-resistant multi-factor authentication on all remote access, VPNs, and administrative accounts to close common ransomware entry vectors.
- Prepare breach-notification and patient-communication workflows in advance, in line with ICO and NHS England guidance, so affected individuals can be identified and warned quickly when impact is confirmed.
Sources: Should East of England patients worry about their stolen data?