The Norfolk and Norwich University Hospital (NNUH), the county's largest hospital, has confirmed that sensitive patient data was stolen and leaked by the Russia-linked cyber-criminal group Qilin. The theft stems from the mid-2024 attack on Synnovis, a third-party pathology and diagnostics provider used across the NHS. Acting executive managing director Chris Cobb confirmed the Trust was notified that NNUH-linked data was among the material accessed, with an estimated tens of thousands of patients potentially affected.
What Happened
Qilin compromised Synnovis, a laboratory partner that tests blood, tissue, and other samples and performs diagnostics for hospitals and GP practices across the NHS. After exfiltrating data, the group published the stolen material on the darknet, a section of the internet routinely used by criminals to leak and trade stolen data. NNUH stated it was notified by Synnovis that data linked to the Trust was included in the breached material, and it is now working to identify every affected individual while following NHS England and Information Commissioner's Office guidance.
The blast radius extends well beyond Norfolk. Hospital Trusts in Essex, Bedfordshire, and London were also caught up in the same Synnovis incident, underscoring the systemic risk created when a single diagnostics vendor sits behind many health providers.
What Was Taken
The compromised data relates to pathology and diagnostic services, the most sensitive category of medical information. Because Synnovis processes blood, tissue, and laboratory samples, the exposed records can tie named individuals to clinical results and treatment context. NNUH estimates tens of thousands of its patients may be implicated, though it is still confirming the precise list of affected individuals.
Notably, Qilin itself described the data as having been stolen "in haste and in a random manner" from its hard drives, an admission that the dataset is likely disorganized but still rich enough to enable extortion and downstream fraud. Action Fraud, the UK's national reporting centre for fraud and cybercrime, has urged anyone contacted by a party claiming to hold their data to report it.
Why It Matters
This incident is a textbook example of third-party supply chain risk in healthcare. NNUH did not have to be breached directly; an attacker only needed to compromise one shared diagnostics vendor to reach patient populations across multiple Trusts spanning Norfolk, Essex, Bedfordshire, and London. For defenders, the lesson is that vendor risk is patient risk, and a single weak link in the diagnostics chain can expose an entire region.
The actor profile raises the stakes further. Qilin claims it targeted Synnovis to punish the UK over an unspecified war, mixing ostensibly political motivation with a financially driven extortion model. That blend makes the group unpredictable: data may be leaked for leverage even when ransom negotiations stall, and victims cannot assume payment removes the exposure.
The Attack Technique
Qilin operates as a ransomware-as-a-service operation that pairs encryption with data exfiltration to pressure victims through double extortion. In this case, the group exfiltrated data from Synnovis systems and published it to a darknet leak site rather than relying on encryption alone. The specific initial access vector into Synnovis has not been publicly disclosed, but Qilin affiliates commonly gain entry through stolen or weak credentials, exposed remote access services, and unpatched internet-facing systems before moving laterally to reach high-value data stores. The group's own description of grabbing files "in haste" from hard drives suggests a rapid smash-and-grab collection stage once inside.
What Organizations Should Do
- Inventory and tier every third-party vendor that processes patient or sensitive data, and require contractual security controls, breach notification timelines, and audit rights for diagnostics and lab partners.
- Enforce phishing-resistant multi-factor authentication on all remote access, VPN, and administrative accounts to close the credential-based entry points Qilin affiliates favor.
- Segment networks so a vendor or partner compromise cannot pivot directly into bulk patient data stores, and restrict access to pathology systems on a least-privilege basis.
- Deploy and tune endpoint and network monitoring to detect large or unusual data staging and exfiltration, the stage where this breach could have been caught before the leak.
- Maintain tested, offline backups and a rehearsed incident response and breach-notification plan aligned with ICO and NHS England guidance so affected individuals are identified quickly.
- Brief patients and staff that fraudsters may exploit leaked data, and direct anyone contacted with breach claims to report it to Action Fraud rather than engaging.
Sources: Data stolen from patients at Norfolk and Norwich hospital | Norwich Evening News