CSIDB logo
Incident

Bedfordshire Hospitals NHS Foundation Trust

Incident posture

Attack window
Jun 2024
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2026-09-07 13:31

Linked entities

Victim
Bedfordshire Hospitals NHS Foundation Trust
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Russia-based cyber-criminal group called Qilin carried out a ransomware attack on Synnovis, a third-party pathology testing provider, stealing confidential patient data from multiple NHS organisations in England. The stolen information, which was later published on the dark web, included names, dates of birth, NHS numbers, postcodes, and test results, and was taken in a hasty and random manner. Among those affected, almost 33,000 patient records were stolen from one NHS trust, while another trust confirmed the breach of 2,380 records relating to specialist diagnostic tests. Synnovis stated there was no evidence the data had been used maliciously, though it continued to notify affected trusts and supported efforts to strengthen cybersecurity defences across impacted organisations.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In June 2024, a major cyber attack targeted Synnovis, a third‑party provider that analysed blood, urine and tissue samples for several NHS hospital trusts in England. The attack disrupted IT and laboratory systems used by a number of London hospitals that relied heavily on the provider for diagnostic testing. A Russia‑based cyber‑criminal group known as Qilin subsequently claimed responsibility for the incident. Data was exfiltrated from computer drives operated by Synnovis and later published on the dark web. Synnovis later stated there was no evidence the stolen information had been used maliciously, characterising the theft as having been carried out "in haste and in a random manner." Chief executive Mark Dollar said Synnovis was offering its "full support" to the affected organisations. The breach was confirmed in June 2024, with subsequent investigations revealing that confidential patient data belonging to multiple NHS trusts had been compromised.

Following the incident, Synnovis undertook a lengthy review of the stolen data in order to identify which NHS organisations and individuals had been affected. The company said it notified all affected NHS trusts, while individual trusts retained responsibility for directly informing patients whose information had been taken. Stolen information could include patient names, dates of birth, patient numbers, NHS numbers, postcodes and test results. Among the trusts impacted was Mid and South Essex NHS Foundation Trust (MSE), which runs Broomfield Hospital in Chelmsford as well as Basildon and Southend hospitals. The trust was notified about the breach in December 2024 and confirmed that 2,380 of its patient records had been involved, with the data relating to specialist diagnostic tests rather than systems run by the trust itself. Dawn Scrafield, deputy chief executive for MSE, said the records affected were a mixture of specialist diagnostic tests, and noted that because some data was not directly linked to patients, confirmation on exact numbers was still outstanding at the time of reporting. The trust committed to contacting any affected individuals once identities had been fully established.

Bedfordshire Hospitals NHS Foundation Trust was also among the organisations affected by the same attack. In June 2026, the trust publicly disclosed that almost 33,000 of its patients had their data stolen in the hack, revealing the scale of the impact on its patient population. The trust was one of an undisclosed number of NHS organisations whose confidential patient data was exposed in the breach. MSE stated that it had brought in cyber security experts to strengthen its own systems in the wake of the incident, even though the stolen data did not originate from systems operated by the trust. The incident underscored the supply chain risk posed by third‑party service providers, as the attackers compromised a single pathology partner and through it gained access to data held by multiple hospital trusts. At the time of public disclosure, Synnovis reiterated that it had notified all affected NHS trusts and that the published data appeared to have been stolen indiscriminately rather than targeted for specific exploitation.

Sources

Sources available to members: 1 source.

CSIDB