CSIDB logo
Incident

Scottish Association for Mental Health

Incident posture

Attack window
Mar 2022
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2025-10-20 00:00

Linked entities

Victim
Scottish Association for Mental Health
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Mar 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Scottish mental health charity experienced a sophisticated ransomware attack claimed by the RansomExx group, which disrupted email systems and phone lines but saw services maintained through alternative channels. The attackers stole approximately 12GB of data, prompting an active investigation involving law enforcement. The organization prioritized service continuity despite operational challenges, condemning the targeting of vulnerable populations while restoring communication systems. RansomExx, known for high-profile attacks but lower publicity focus, typically avoids systems using Russian or CIS languages.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On March 17, 2022, the Scottish Association for Mental Health (SAMH) experienced a ransomware attack claimed by the RansomExx group, disrupting email systems and phone lines at national and local offices. The organization first publicly acknowledged the incident on March 18 through an initial statement confirming cybersecurity issues affecting communications infrastructure. By March 21, SAMH Chief Executive Billy Watson issued a detailed announcement describing the event as a "sophisticated and criminal cybersecurity attack" that devastated the charity. RansomExx listed SAMH on its leak site and claimed to have stolen approximately 12GB of data during the breach, though specific data types were not disclosed. The attack temporarily impaired organizational communications while local in-person and phone services remained operational across SAMH's 60 Scottish community locations.

SAMH immediately engaged Police Scotland and cybersecurity experts to investigate the active incident, with Watson emphasizing continuity of mental health services for vulnerable populations as the top priority. Staff implemented contingency measures to minimize service disruptions despite compromised digital systems. The ransomware group's involvement was confirmed by Emsisoft threat analyst Brett Callow, who noted RansomExx's history of targeting high-profile entities like Taiwan's GIGABYTE and Brazil's Lojas Renner while avoiding systems using Russian or CIS languages. Recovery efforts restored email functionality and affected phone lines by March 21, though the organization maintained contact through alternative channels throughout the disruption. No ransom payment details or data release confirmation were provided, with SAMH continuing to cooperate with law enforcement and advisors to manage consequences of the attack.

Sources

Sources available to members: 2 sources.

CSIDB