SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
▣ Breach EAST-OF-ENGLAND 2026-06-11

Synnovis: Qilin Ransomware NHS Data Breach

"Tens of thousands of NHS patients across the East of England have had their personal data stolen in the fallout from the June 2024 ransomware attack on Synnovis, a third-party pathology and testing provider serving NHS…"

Tens of thousands of NHS patients across the East of England have had their personal data stolen in the fallout from the June 2024 ransomware attack on Synnovis, a third-party pathology and testing provider serving NHS hospitals and GPs. The Russian cyber-criminal group Qilin uploaded roughly 400GB of sensitive information to its darknet leak site after the intrusion. The incident, described by experts as one of the most significant and harmful cyber-attacks ever carried out in the UK, has continued to widen, with trusts in Essex, Bedfordshire, London and now Norfolk all confirmed as affected.

What Happened

In June 2024, criminals broke into the computer systems of Synnovis, a provider that tests blood, tissue, and other samples and performs laboratory diagnostics for NHS hospitals and GPs. According to Synnovis, the attackers gained access in an attempt to extort the company for money in a classic ransomware playbook. When extortion efforts stalled, Qilin published approximately 400GB of stolen data to its darknet site.

The blast radius has grown steadily in the two years since. King's College Hospital NHS Foundation Trust and Guy's and St Thomas' NHS Foundation Trust were the first to disclose impact. On 2 June it emerged Bedfordshire Hospitals NHS Foundation Trust had nearly 33,000 records stolen. Mid and South Essex NHS Foundation Trust later confirmed 2,380 of its records were affected, and the BBC has now learned patients at Norfolk and Norwich University Hospitals Foundation Trust were also caught in the breach. Synnovis said in March that it had notified the organisations whose data had been affected.

What Was Taken

Qilin exfiltrated around 400GB of sensitive information from Synnovis hard drives. Synnovis characterised the theft as having been carried out "in haste and in a random manner," meaning the stolen material was not cleanly curated but pulled in bulk from computer drives. Given Synnovis processes blood, tissue, and diagnostic samples, the exposed records carry the potential for highly sensitive health-related and personally identifiable information.

Confirmed record counts so far include nearly 33,000 records at Bedfordshire Hospitals and 2,380 at Mid and South Essex, on top of earlier disclosures at the London trusts. NHS England, when asked which trusts had patient data stolen and how many individuals were affected, referred inquiries back to Synnovis, indicating the full scope of impacted individuals is still being tallied.

Why It Matters

This breach demonstrates how a single third-party supplier can become a systemic point of failure across an entire national health system. One compromise at Synnovis cascaded into patient-data exposure spanning multiple NHS trusts in different regions, and the list of affected organisations is still growing two years later. For defenders, it is a stark reminder that an organisation's risk surface extends to every vendor that touches sensitive data.

The healthcare sector remains a priority target for financially motivated ransomware crews because of the criticality of its operations and the sensitivity of its data. Qilin told the BBC via an encrypted messaging service that it had deliberately targeted Synnovis to "punish" the UK over an unspecified war, but cyber security expert Ciaran Martin dismissed that claim as "absolute garbage," stating the group's aims were "entirely financial." Defenders should treat the political framing as cover and plan against the real motive: extortion-driven data theft.

The Attack Technique

Public reporting confirms this was a ransomware and data-exfiltration operation run by Qilin, a Russian cyber-criminal group, with the specific initial-access vector not disclosed in the reporting. The hallmarks are consistent with Qilin's known double-extortion model: compromise the victim's systems, steal data in bulk, and pressure for payment under threat of public leak. When Synnovis did not pay, Qilin followed through by posting the stolen 400GB to its darknet site.

The fact that data was described as taken "in haste and in a random manner" suggests the attackers prioritised rapid bulk exfiltration over selective targeting, a pattern common when operators want to maximise leverage before detection or containment. Even without a confirmed entry point, the case underscores the importance of hardening third-party and supply-chain access paths.

What Organizations Should Do

Sources: Should East of England patients worry about their stolen data?